Ivanti Used AI to Find a Perfect-Score Security Flaw in Its Own Software. Here Is What That Means.
The company quietly ran an AI project starting in March and says the results are already surprising even its own security chief.

Key points
- Ivanti disclosed CVE-2026-10520, a critical flaw in its Sentry mobile gateway product, in May 2025, with a perfect severity score of 10 out of 10.
- An AI language model, not a human researcher or engineer, discovered the flaw.
- Ivanti began its internal AI security project in the first week of March 2025, using models from Anthropic and OpenAI.
- Ivanti's chief security officer told Dark Reading he suspects a bug-bounty report the company received was written by an AI using a roughly $100-per-month software subscription.
- The company says it plans to release research figures on vulnerabilities found and fixed in the coming months.
A software company used an artificial intelligence model, a type of computer program that generates text and can reason through complex problems, to find a critical flaw in its own product before any criminal did. That company is Ivanti, which makes networking and security software used by businesses and governments worldwide.
The flaw it found is tracked as CVE-2026-10520. It sits inside Ivanti's Sentry product, a piece of software that acts as a gateway controlling access from mobile phones to corporate systems. The flaw received a CVSS, or Common Vulnerability Scoring System, score of 10 out of 10. That is the highest possible rating, meaning attackers who found it first could have taken full control of affected systems.
No human found it. The AI did.
How did Ivanti get an AI to hunt for security flaws?
Ivanti's chief security officer, Daniel Spicer, says the project started informally in late February 2025 when he and a colleague noticed that newer AI models, specifically Anthropic's Claude generation 4.6, had become capable enough to handle real security work. The formal internal project launched in the first week of March.
The team split the work into two tracks. One track focused on finding flaws that existing automated scanning tools were missing. The other focused on fixing flaws automatically, before a human engineer even had to look at them.
On the fixing side, the process works like this. Ivanti's existing code-scanning tools flag a weakness in the software. Instead of sending a human engineer to fix it, the AI agent picks up the problem, writes a corrected version of the code, then passes it back to the scanner to confirm the flaw is gone. If the scanner agrees, automated tests check that the fix did not break anything else. Only then does the code go back to an engineer.
Spicer told Dark Reading the AI operates inside a tightly limited space. It receives a single clearly defined task and cannot freely access Ivanti's wider systems. That design prevents the kind of runaway AI behaviour that has caused problems at other organisations.
Ivanti is using models from both Anthropic and OpenAI, as well as some open-source models run internally.
The same capability cuts both ways, though. Spicer said a bug-bounty report, where an outside researcher submits a discovered flaw to claim a cash reward, arrived recently and the formatting looked like it came from an Anthropic Opus model. The flaw was one Ivanti had already spotted, so no harm was done. But the economics are striking: a $100-per-month AI subscription could help someone earn a $5,000 to $10,000 bug-bounty payout.
For ordinary customers who use products that run on Ivanti software, the practical advice is straightforward. Check that your IT team or software vendor has applied the Ivanti Sentry patch covering CVE-2026-10520. If you use a corporate VPN or mobile device management system at work, ask your IT contact whether Ivanti Sentry is part of the setup and whether it is up to date.



