discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Max severity Ivanti Sentry vulnerability now exploited in attacks

Attackers are targeting a newly patched Ivanti Sentry flaw that can lead to root code execution on internet-exposed gateways.

By Sergiu Gatlan·Jun 11·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Max severity Ivanti Sentry vulnerability now exploited in attacks
Image: bleepingcomputer.com

Ivanti patched a maximum-severity command-injection bug in Sentry, but Shadowserver says exploitation began almost immediately using a public proof of concept. The concern is that exposed gateways may already be compromised, while Ivanti’s advisory has not yet been updated to reflect active attacks.

Why it matters

This is a high-risk edge-device vulnerability in software that sits between mobile users and corporate systems. If attackers get in, they can use the gateway as a foothold inside enterprise networks and steal sensitive data.

A gatekeeper for company phones had a broken lock, and thieves started trying it right away. If they get through, it is like sneaking in through the front door of a building instead of climbing a fence.

Analysis

What happened

Ivanti patched CVE-2026-10520 in Sentry on Tuesday, releasing versions R10.5.2, R10.6.2, and R10.7.1. The flaw is described as an OS command injection issue and carries maximum severity because it can allow code execution as root on internet-exposed systems.

Why the alert escalated

Ivanti said it had no evidence of exploitation at disclosure, but Shadowserver reported the next day that attackers were already abusing the flaw. In a public warning, Shadowserver said it was seeing “a large amount” of exploitation attempts based on a public proof of concept and that, of the instances it could scan, some were already backdoored. It also warned that its view may be incomplete because some Sentry systems are not reachable from its scans.

Why Sentry matters

Sentry, formerly MobileIron Sentry, is used as a secure gateway between back-end corporate systems and remote mobile devices. That placement makes it a valuable target: compromising it can provide an entry point into enterprise networks and expose sensitive customer and corporate data.

Wider context

The article notes that Ivanti products have been repeatedly targeted in recent years. CISA has flagged 34 vulnerabilities across Ivanti products as actively exploited in the wild, and 12 of those were also used in ransomware attacks. That history raises the urgency for administrators to patch quickly and assume exposed systems may already be at risk.

Key points

  • Ivanti patched CVE-2026-10520 in Sentry, a maximum-severity command-injection vulnerability.
  • The bug can allow root-level code execution on internet-exposed secure mobile gateways.
  • Shadowserver reported active exploitation attempts shortly after the patch, based on a public proof of concept.
  • Shadowserver said some exposed instances it found were already backdoored, though its scans may undercount real exposure.
  • The article places the issue in the context of repeated Ivanti exploitation and past CISA alerts.
The Upside

Ivanti has already released fixed Sentry versions, so organizations that patch quickly can close the hole before more damage spreads. Shadowserver’s reporting may also help defenders identify exposed systems and focus response on likely compromised gateways.

The Downside

If admins delay patching, the article suggests exposed systems are likely already compromised or at least under active attack. Because the flaw can grant root-level code execution on a gateway, attackers may be able to pivot into internal corporate systems and steal data.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechpolicy

Author

Sergiu Gatlan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 11, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechpolicy

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…