CVE-2026-10520

CRITICALCVSS 10.0100% EPSSKEV — known exploited🧨 Public exploit (GreyNoise)

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Published 2026-06-09 · last modified 2026-07-23

Affected products

VendorProduct
ivantistandalone_sentry

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.