CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today
Defender actions
- Patch Ivanti Sentry to R10.5.2 / R10.6.2 / R10.7.1 today, and restrict the MICS API (port 8443) to management IPs; CVE-2026-10520 is an unauthenticated root RCE with a working public PoC released the same day; given Sentry fronts Exchange/managed-device access in government estates, treat the exploitation window as hours, not days.
- Patch internet-exposed Ivanti Sentry now and compromise-assess, do not just patch (CVE-2026-10520). Upgrade to R10.5.2 / R10.6.2 / R10.7.1, restrict the MICS listener to management networks, and because exposed gateways are confirmed backdoored, audit for persistence (unexpected cron entries,
authorized_keyschanges, anomalous children of the MICS Java process) before declaring any instance clean. Pre-auth CVSS 10.0 RCE with confirmed in-the-wild backdooring.
Analysis
CVE-2026-10520 is an unauthenticated OS command injection in Ivanti Sentry (formerly MobileIron Sentry), the EMM/MDM enforcement gateway that proxies email and applications to managed devices and frequently fronts Exchange. The vulnerable endpoint is /mics/api/v2/sentry/mics-config/handleMessage on the MICS admin API (port 8443): ConfigServiceController.handleMessage() accepts XML payloads containing commandexec blocks whose reqandres field is passed unvalidated through ConfigRequestProcessor.handleExecute() into native command execution, yielding root-level RCE with no authentication (watchTowr, 2026-06-10). watchTowr published the technical analysis and a working PoC on 2026-06-10; CVE-2026-10523 is a companion authentication bypass (CWE-288) covered in the same Ivanti advisory (watchTowr, 2026-06-10). No in-the-wild exploitation is confirmed yet, but a same-day public PoC against a pre-auth root RCE on a government-grade MDM gateway sharply compresses the window. Affected: all Sentry before R10.5.2 / R10.6.2 / R10.7.1; patch immediately and restrict the MICS interface (8443) to management IPs in the interim (T1190, T1059.004).
Cited evidence
Shadowserver Foundation observed a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC by watchTowr, and said that at least two of the 19 vulnerable instances they are seeing have been backdoored
CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
Updates1
The Ivanti Sentry MICS command-injection covered last week as an advisory-plus-patch story is now confirmed exploited. After watchTowr published a working proof-of-concept on 10 June, the Shadowserver Foundation observed mass exploitation attempts and confirmed that at least two of the then-19 internet-exposed Sentry instances had been backdoored shortly after the PoC went public (Security Affairs, 2026-06-11).
The flaw (CVSS 10.0) is reachable by an unauthenticated POST to the MICS handleMessage interface and executes arbitrary OS commands as root, giving an attacker control over every mailbox, calendar and enterprise application the gateway brokers (T1190 Exploit Public-Facing Application; T1505.003 Web Shell post-exploitation). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 11 June and CERT-EU issued advisory 2026-008 urging immediate upgrade (CERT-EU 2026-008, 2026-06-10; BleepingComputer, 2026-06-12). The operational driver is the confirmed in-the-wild backdooring, not any compliance date: any internet-reachable Sentry should be treated as presumed-compromised and compromise-assessed, not merely patched. Affected: Sentry ≤ R10.5.1, ≤ R10.6.1, ≤ R10.7.0; fixed in R10.5.2 / R10.6.2 / R10.7.1. See the § 0 Immediate Action callout and § 6.
Sources4
Revision history
- Published 2026-06-10-c84347b2
- Update 2026-06-14-e1d80e78
Ivanti Sentry CVE-2026-10520 (CVSS 10.0, pre-auth OS command injection) is being exploited in the wild; Shadowserver confirmed at least two internet-exposed gateways were backdoored shortly after the public PoC. CISA added it to KEV on 11–12 June; Swiss/EU public-sector MDM estates running Sentry ≤ R10.5.1 / ≤ R10.6.1 / ≤ R10.7.0 must patch and compromise-assess now (Security Affairs, 2026-06-11).
Changed: actions cves evidence immediate_action priority sources tags body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.