Ivanti: Max severity Sentry flaw allows code execution as root
Ivanti patched two critical Sentry flaws, including a max-severity bug that can let remote attackers run code as root.
Intelligence analysis by GPT-5.4 Mini

Ivanti fixed an OS command injection flaw and an auth bypass in Sentry, its secure mobile gateway appliance. The company says it has no evidence of exploitation so far and urges customers to upgrade.
Ivanti found two big holes in a security gate for company phones and networks. One hole could let a stranger take over the gate like a master key, and the other could let them run dangerous commands like they were the boss.
Analysis
Ivanti says it has patched two critical vulnerabilities in Sentry, its secure mobile gateway appliance formerly known as MobileIron Sentry. The highest-severity issue, tracked as CVE-2026-10520, is an OS command injection flaw that can let a remote attacker execute code with root privileges.
The second bug, CVE-2026-10523, is an authentication bypass. According to the article, an unauthenticated attacker could exploit it remotely to create rogue administrative accounts and gain full administrative access.
Ivanti released fixes in Sentry versions R10.5.2, R10.6.2, and R10.7.1. The company said it is not aware of customers being exploited by these vulnerabilities at the time of disclosure and said there is no known public exploitation that would provide indicators of compromise.
The story also places the bugs in context: Ivanti vulnerabilities have often been used in real-world attacks because they can give cybercriminals an easy entry point into enterprise networks and the sensitive data those networks hold. The article points to recent zero-day activity against Ivanti products, including an Endpoint Manager Mobile flaw that CISA told U.S. federal agencies to patch in May.
For defenders, the practical takeaway is straightforward: treat Sentry as urgent patching territory, especially if the appliance is reachable from untrusted networks. The combination of root-level code execution and remote administrative takeover makes both flaws high-risk even before any public exploitation appears.
Key points
- Ivanti patched two critical Sentry vulnerabilities, including a maximum-severity OS command injection flaw.
- CVE-2026-10520 can let a remote attacker execute code with root privileges.
- CVE-2026-10523 is an authentication bypass that could let an attacker create rogue admin accounts.
- Ivanti says it has no evidence of customer exploitation at the time of disclosure.
- The company released fixes in Sentry versions R10.5.2, R10.6.2, and R10.7.1.
If organizations patch quickly, they can close off both the root-level code execution path and the admin takeover bug before attackers get a broad foothold. Ivanti also says it has no evidence of active exploitation so far, which gives defenders a window to respond.
If patching is delayed, attackers could use either flaw to break into exposed Sentry systems and move into corporate networks. The article notes that Ivanti vulnerabilities have repeatedly been used in attacks, so even newly disclosed bugs can become attractive targets fast.



