CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive

BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
Share

Key points

  • CISA has ordered federal civilian agencies to patch an actively exploited Ivanti Sentry flaw within three days under the newly issued Binding Operational Directive, BOD 26-04.
  • BOD 26-04 compresses the patch window for bugs CISA explicitly tags as urgent, replacing the longer timelines agencies relied on under earlier directives.
  • Sentry brokers authentication for downstream mobile services, so a compromised appliance lets attackers operate below the layer where conditional access policies live.
  • The three-day clock applies to KEV entries CISA explicitly tags under BOD 26-04, not to every Known Exploited Vulnerabilities catalog entry retroactively.
  • The directive binds FCEB agencies; everyone else should treat it as strongly worded advice.

What is Ivanti Sentry and why does it matter?

Ivanti Sentry, formerly MobileIron Sentry, sits in front of mobile device management deployments and brokers ActiveSync and other backend traffic. In IAM terms it's a gateway that often holds credentials and session material for an entire mobile fleet. Compromising it is rarely a single-user problem.

Should you worry about MFA protecting you here?

Not on its own. If the Sentry appliance itself is owned, the attacker is operating below the layer where your conditional access policies live. Phishing-resistant MFA on user accounts is good. It doesn't save you when the authenticator-adjacent infrastructure is the thing being exploited.

What has changed under BOD 26-04?

When we covered BOD 26-04 on 10 June, the directive's four-factor framework prioritised internet exposure and active exploitation over raw severity scores. This Ivanti Sentry order is that framework's first enforcement action, and it shows how the compressed timeline works in practice. Under the old regime, teams could batch KEV-listed CVEs into a normal change window. That comfort is now gone for the subset of bugs CISA deems most dangerous.

Ivanti has published a fix and configuration guidance in its security advisory portal. Any internet-reachable Sentry instance should be treated as suspect until it's patched and reviewed.

What should identity teams do now?

Two actions are worth doing now, even outside the federal perimeter. First, inventory every Sentry appliance including forgotten lab instances, because internet exposure is the aggravating factor. Second, rotate any service-account credentials and certificates the appliance touched, and assume cached session tokens are burned.

CISA's Known Exploited Vulnerabilities catalog is the authoritative list of what the directive covers.

Ivanti edge appliances have been a recurring entry point for state-aligned intrusions over the past two years. Treating them as crown-jewel infrastructure, patched fast, monitored hard, isolated from the rest of the identity plane, is the only posture that makes sense at this point.

© 2026 Threat Vectr