a perfect 10: the Ivanti Sentry bug that hands an anonymous attacker root, and it's already being backdoored

CVE-2026-10520 scores a maximum 10.0 — the rarest severity rating there is. No login, one network request, and an attacker owns the box as root.…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: an OS command injection (CWE-78) in Ivanti Sentry that gives a remote, unauthenticated attacker root-level remote code execution.

What you need to know

Affected: Ivanti Sentry before R10.5.2, versions 10.6.0–10.6.1, and 10.7.0.

What you need to know

Fixed in: R10.5.2, R10.6.2, and R10.7.1 — patch to one of these immediately.

What you need to know

Actively exploited: on CISA's Known Exploited Vulnerabilities catalog, with public PoC code and confirmed backdoored instances.

What you need to know

If you can't patch this hour: take the appliance off the public internet. An exposed, unpatched Sentry should be considered compromised.

Assume compromise, don't just patch

Because this is exploited in the wild with public code and confirmed backdoors, patching is necessary but not sufficient. If your Sentry was internet-facing and unpatched at any point since early…

Aliteq

Read the full story

a perfect 10: the Ivanti Sentry bug that hands an anonymous attacker root, and it's already being backdoored

Read the full story on Aliteq