News Article · Jun 12, 2026 at 5:13 PM
2 min read 0
Member
Ivanti Sentry Zero-Day Exploited in Attacks, Shadowserver Reports Widespread Compromise
Security #zero-day #remote code execution #Shadowserver #ivanti #CVE-2026-10520 #mobile gateway #enterprise security

Ivanti Sentry Zero-Day Exploited in Attacks, Shadowserver Reports Widespread Compromise

A critical Ivanti Sentry vulnerability (CVE-2026-10520) is being actively exploited in the wild, with Shadowserver reporting that most internet-exposed instances may be compromised. The flaw allows root-level code execution.

Listen to this article 3 min

Attackers are actively exploiting a maximum-severity vulnerability in Ivanti Sentry, a secure mobile gateway formerly known as MobileIron Sentry, to execute code with root privileges on internet-exposed appliances. The flaw, tracked as CVE-2026-10520, was patched by Ivanti on June 10, 2026, but the Shadowserver Foundation reported the next day that exploitation attempts were already widespread.

Shadowserver observed 19 vulnerable instances in its scans, with at least two confirmed backdoored. The organization warned that all remaining exposed gateways are likely compromised, noting that its detection is limited because many Ivanti Sentry instances blocklist its search engine.

Root-Level Code Execution via OS Command Injection

The vulnerability stems from an OS command injection weakness in Ivanti Sentry, allowing unauthenticated attackers to execute arbitrary commands as root. Ivanti released patches in versions R10.5.2, R10.6.2, and R10.7.1. At the time of disclosure, the company stated it had no evidence of exploitation, but public proof-of-concept code quickly followed, enabling mass scanning and attacks.

  • CVE-2026-10520 carries a CVSS score of 10.0, the highest severity rating.
  • Ivanti Sentry secures traffic between corporate back-end systems and remote mobile devices.
  • Shadowserver reported that most internet-exposed Sentry instances are likely backdoored.
  • Ivanti has not updated its advisory to reflect active exploitation as of June 11.
  • Ivanti products have been flagged in 34 actively exploited vulnerabilities by CISA over the past several years.

Broader Threat Landscape: Oracle, ServiceNow, and Critical Infrastructure

The Ivanti attacks come amid a surge in security incidents targeting enterprise software. The ShinyHunters extortion gang is actively hacking Oracle PeopleSoft servers, claiming data theft from over 100 organizations. Separately, bug bounty research on ServiceNow inadvertently triggered false security alerts, causing organizations to believe they were breached. In Australia, a cyberattack shut down major sugar mills operated by the country's second-largest sugar producer, disrupting harvest operations. Meanwhile, the China-linked JDY botnet, associated with Volt Typhoon, has expanded its targeting of U.S. military networks, increasing reconnaissance efforts.

Organizations using Ivanti Sentry should immediately apply the available patches and assume compromise if their gateways were exposed. CISA has previously ordered federal agencies to patch Ivanti flaws within days, and similar urgency is warranted for this vulnerability. Ivanti's products are used by over 40,000 customers worldwide, making the attack surface significant.

Fact check

  • CVE-2026-10520 is a maximum-severity OS command injection vulnerability in Ivanti Sentry with a CVSS score of 10.0.

    verified · source

  • Shadowserver reported that most internet-exposed Ivanti Sentry instances are likely backdoored.

    reported · source

  • Ivanti has not updated its security advisory to reflect active exploitation as of June 11, 2026.

    reported · source

  • The ShinyHunters extortion gang is actively hacking Oracle PeopleSoft servers, claiming data theft from over 100 organizations.

    reported · source

  • A cyberattack shut down major Australian sugar mills, disrupting harvest operations.

    reported · source

Source reporting (8)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 112 users online: 0 registered, 104 guests and 8 bots.

Most users ever online was 186 on 12 Jun 2026, 5:49 pm.

Bots: AhrefsBot Applebot Bingbot Facebook Other Bot Other Crawler SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 350