Max severity Ivanti Sentry vulnerability now exploited in attacks
Attackers are targeting a newly patched Ivanti Sentry flaw that can lead to root code execution on internet-exposed gateways.
Intelligence analysis by GPT-5.4 Mini

Ivanti patched a maximum-severity command-injection bug in Sentry, but Shadowserver says exploitation began almost immediately using a public proof of concept. The concern is that exposed gateways may already be compromised, while Ivanti’s advisory has not yet been updated to reflect active attacks.
A gatekeeper for company phones had a broken lock, and thieves started trying it right away. If they get through, it is like sneaking in through the front door of a building instead of climbing a fence.
Analysis
What happened
Ivanti patched CVE-2026-10520 in Sentry on Tuesday, releasing versions R10.5.2, R10.6.2, and R10.7.1. The flaw is described as an OS command injection issue and carries maximum severity because it can allow code execution as root on internet-exposed systems.
Why the alert escalated
Ivanti said it had no evidence of exploitation at disclosure, but Shadowserver reported the next day that attackers were already abusing the flaw. In a public warning, Shadowserver said it was seeing “a large amount” of exploitation attempts based on a public proof of concept and that, of the instances it could scan, some were already backdoored. It also warned that its view may be incomplete because some Sentry systems are not reachable from its scans.
Why Sentry matters
Sentry, formerly MobileIron Sentry, is used as a secure gateway between back-end corporate systems and remote mobile devices. That placement makes it a valuable target: compromising it can provide an entry point into enterprise networks and expose sensitive customer and corporate data.
Wider context
The article notes that Ivanti products have been repeatedly targeted in recent years. CISA has flagged 34 vulnerabilities across Ivanti products as actively exploited in the wild, and 12 of those were also used in ransomware attacks. That history raises the urgency for administrators to patch quickly and assume exposed systems may already be at risk.
Key points
- Ivanti patched CVE-2026-10520 in Sentry, a maximum-severity command-injection vulnerability.
- The bug can allow root-level code execution on internet-exposed secure mobile gateways.
- Shadowserver reported active exploitation attempts shortly after the patch, based on a public proof of concept.
- Shadowserver said some exposed instances it found were already backdoored, though its scans may undercount real exposure.
- The article places the issue in the context of repeated Ivanti exploitation and past CISA alerts.
Ivanti has already released fixed Sentry versions, so organizations that patch quickly can close the hole before more damage spreads. Shadowserver’s reporting may also help defenders identify exposed systems and focus response on likely compromised gateways.
If admins delay patching, the article suggests exposed systems are likely already compromised or at least under active attack. Because the flaw can grant root-level code execution on a gateway, attackers may be able to pivot into internal corporate systems and steal data.



