CISA orders feds to patch actively exploited Ivanti flaw by Sunday
CISA gave federal agencies three days to patch an Ivanti Sentry flaw that is now being exploited in attacks.
Intelligence analysis by GPT-5.4 Mini

CISA has added Ivanti Sentry CVE-2026-10520 to its Known Exploited Vulnerabilities list and told federal civilian agencies to fix it within three days under Binding Operational Directive 26-04. Shadowserver says attackers are already abusing public proof-of-concept code.
CISA found a serious crack in an Ivanti security box that sits at the front door of networks. Hackers are already trying to slip through it, so federal agencies have to fix it very fast, like putting a lock on a door before thieves get inside.
Analysis
What happened
CISA said CVE-2026-10520 in Ivanti Sentry is being actively exploited and placed it in the Known Exploited Vulnerabilities catalog. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must secure affected systems within three days.
The flaw is described as a maximum-severity OS command injection issue in Ivanti's security gateway appliance, previously known as MobileIron Sentry. Ivanti released patches on Wednesday and initially said it had no evidence of in-the-wild exploitation, but Shadowserver reported that attackers had already backdoored many exposed gateways.
Shadowserver says it can currently see a little over 50 Sentry admin portals exposed online, though it believes the real number is higher because some organizations may be blocking its scans. It warned that systems that were not already patched are likely compromised.
CISA said vulnerabilities like this are a common path for malicious actors and pose significant risk to the federal enterprise. The agency also told stakeholders to follow the BOD 26-04 guidance for cloud services or stop using the product if mitigations are not available.
The directive is notable because it is the first vulnerability CISA has said falls under the new BOD 26-04 rules. The article also notes that CISA has repeatedly singled out Ivanti flaws in recent years, including dozens across different Ivanti products, with some linked to ransomware groups.
Key points
- CISA says CVE-2026-10520 is actively exploited and must be patched within three days by affected federal agencies.
- The flaw affects Ivanti Sentry, a security gateway appliance formerly called MobileIron Sentry.
- Shadowserver says attackers were already abusing public proof-of-concept code and may have backdoored exposed systems.
- Ivanti had patched the issue but had not updated its advisory to say it was under active attack at the time of the report.
- CISA says internet exposure and exploitability are key factors under the new Binding Operational Directive 26-04.
If agencies patch quickly, exposed Ivanti systems can be taken off the easy-target list before more attackers move in. CISA's 3-day deadline also creates strong pressure for faster response across federal environments.
If organizations miss the deadline or cannot patch exposed systems in time, attackers may keep using the flaw to gain access. Shadowserver's warning suggests that unpatched instances may already be compromised, which raises the risk of persistence even after remediation.



