Ivanti Sentry Carries Two Critical Bugs — One a Perfect 10 — Enabling Full Appliance Takeover
A pair of unauthenticated flaws in the mobile gateway give attackers a clear path to root. Exploit code is already public.

Ivanti has patched two critical vulnerabilities in Sentry, its secure mobile gateway product previously marketed as MobileIron Sentry. Both flaws allow unauthenticated remote attackers to seize full control of affected appliances. Patches landed this week. No exploitation has been confirmed in the wild — yet.
The more severe of the two, CVE-2026-10520, is a command injection flaw that leads directly to remote code execution with root privileges on the underlying OS. No authentication required. CVSS scores it a perfect 10. Researchers at watchTowr have already published a detailed breakdown of the issue and released a Python proof-of-concept script organisations can use to test their own deployments. The exploit is, by their characterisation, trivial to execute.
The second vulnerability, CVE-2026-10523, was credited to researcher Bryan Lam. It carries a CVSS score of 9.9. The flaw lets an unauthenticated attacker bypass authentication entirely and create arbitrary administrative accounts on the appliance. Paired with the command injection bug, an attacker gets both a door and the keys.
Sentry sits at the enterprise network edge. It manages, encrypts, and secures traffic between mobile devices and back-end servers — Microsoft Exchange being the textbook deployment. It works alongside Ivanti's Endpoint Manager Mobile to enforce device verification and access controls. Internet-facing by design. That exposure profile matters enormously here.
Both vulnerabilities were reported to Ivanti through its responsible disclosure programme. The company says it has no evidence of active exploitation. That window is narrowing fast given the public proof-of-concept.
Ivanti's track record on this front is worth noting. State-sponsored groups and opportunistic ransomware crews alike have repeatedly targeted Ivanti's network-edge products — Ivanti Connect Secure, Ivanti Policy Secure — after patch disclosures, sometimes within days. The pattern is well-established enough that U.S. federal agencies have issued emergency directives over prior Ivanti flaws.
Affected customers should upgrade to Sentry versions 10.5.2, 10.6.2, or 10.7.1 immediately. Sitting on a vulnerable, internet-exposed gateway with working exploit code circulating publicly is not a defensible posture.



