---
schema: 1
kind: vulnerability
title: >
  CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth OS command injection to root (CVSS
  10.0), public PoC published today
headline: >
  CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth OS command injection to root (CVSS
  10.0), public PoC published today
summary: >
  Ivanti Sentry pre-auth root RCE (CVE-2026-10520, CVSS 10.0) — public PoC published today.
  watchTowr released a full technical write-up and a working GitHub PoC for an unauthenticated OS
  command injection in the MICS admin API of this MDM/EMM gateway, widely deployed in CH/EU
  government. Patch to R10.5.2 / R10.6.2 / R10.7.1 now (watchTowr, 2026-06-10).
discovered_at: "2026-06-10T05:00:04Z"
updated_at: "2026-06-14T05:00:06Z"
event_date: 2026-06-10
run_id: 2026-06-10-c84347b2
priority: critical
immediate_action:
  title: patch Ivanti Sentry now and hunt for an implanted gateway
  action: >
    CVE-2026-10520 is an unauthenticated CVSS 10.0 OS command-injection in the Ivanti Sentry MICS
    interface that yields root on the appliance; shortly after watchTowr's public proof-of-concept
    the Shadowserver Foundation observed mass exploitation attempts and confirmed at least two of
    the then-19 internet-exposed instances had already been backdoored (Security Affairs,
    2026-06-11; CERT-EU 2026-008, 2026-06-10). A root compromise of Sentry exposes every mailbox,
    calendar and enterprise application the gateway brokers.
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - auth-bypass
  - poc-public
  - actively-exploited
  - cisa-kev
regions:
  - switzerland
  - europe
  - global
sectors:
  - public-sector
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-10520
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
  - id: CVE-2026-10523
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/"
    publisher: "watchTowr, 2026-06-10"
    role: primary
  - url: "https://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html"
    publisher: Security Affairs
    role: primary
  - url: "https://cert.europa.eu/publications/security-advisories/2026-008/"
    publisher: CERT-EU 2026-008
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/"
    publisher: BleepingComputer
    role: corroborating
closed_sources: []
evidence:
  - quote: "Shadowserver Foundation observed a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC by watchTowr, and said that at least two of the 19 vulnerable instances they are seeing have been backdoored"
    publisher: Security Affairs
  - quote: CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14
    publisher: Security Affairs
verification: single-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Patch Ivanti Sentry to R10.5.2 / R10.6.2 / R10.7.1 today, and restrict the MICS API (port 8443) to management IPs** — CVE-2026-10520 is an unauthenticated root RCE with a working public PoC released the same day; given Sentry fronts Exchange/managed-device access in government estates, treat the exploitation window as hours, not days."
  - "**Patch internet-exposed Ivanti Sentry now and compromise-assess — do not just patch (CVE-2026-10520).** Upgrade to R10.5.2 / R10.6.2 / R10.7.1, restrict the MICS listener to management networks, and because exposed gateways are confirmed backdoored, audit for persistence (unexpected cron entries, `authorized_keys` changes, anomalous children of the MICS Java process) before declaring any instance clean. Pre-auth CVSS 10.0 RCE with confirmed in-the-wild backdooring."
updates:
  - at: "2026-06-14T05:00:06Z"
    run_id: 2026-06-14-e1d80e78
    type: update
    summary: >
      Ivanti Sentry CVE-2026-10520 (CVSS 10.0, pre-auth OS command injection) is being exploited in
      the wild — Shadowserver confirmed at least two internet-exposed gateways were backdoored shortly
      after the public PoC. CISA added it to KEV on 11–12 June; Swiss/EU public-sector MDM estates
      running Sentry ≤ R10.5.1 / ≤ R10.6.1 / ≤ R10.7.0 must patch and compromise-assess now (Security
      Affairs, 2026-06-11).
    fields:
      - actions
      - cves
      - evidence
      - immediate_action
      - priority
      - sources
      - tags
      - body
    merged_from: 2026-06-14/ivanti-sentry-cve-2026-10520-exploitation-confirmed-in-the-w
migrated_from: briefs/2026-06-10.md
---

CVE-2026-10520 is an unauthenticated OS command injection in Ivanti Sentry (formerly MobileIron Sentry), the EMM/MDM enforcement gateway that proxies email and applications to managed devices and frequently fronts Exchange. The vulnerable endpoint is `/mics/api/v2/sentry/mics-config/handleMessage` on the MICS admin API (port 8443): `ConfigServiceController.handleMessage()` accepts XML payloads containing `commandexec` blocks whose `reqandres` field is passed unvalidated through `ConfigRequestProcessor.handleExecute()` into native command execution, yielding root-level RCE with no authentication ([watchTowr, 2026-06-10](https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/)). watchTowr published the technical analysis and a working PoC on 2026-06-10; CVE-2026-10523 is a companion authentication bypass (CWE-288) covered in the same Ivanti advisory ([watchTowr, 2026-06-10](https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/)). No in-the-wild exploitation is confirmed yet, but a same-day public PoC against a pre-auth root RCE on a government-grade MDM gateway sharply compresses the window. Affected: all Sentry before R10.5.2 / R10.6.2 / R10.7.1; patch immediately and restrict the MICS interface (8443) to management IPs in the interim (T1190, T1059.004).

## Update — 2026-06-14T05:00:06Z

The Ivanti Sentry MICS command-injection covered last week as an advisory-plus-patch story is now confirmed exploited. After watchTowr published a working proof-of-concept on 10 June, the Shadowserver Foundation observed mass exploitation attempts and confirmed that at least two of the then-19 internet-exposed Sentry instances had been backdoored shortly after the PoC went public ([Security Affairs, 2026-06-11](https://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html)).

The flaw (CVSS 10.0) is reachable by an unauthenticated POST to the MICS `handleMessage` interface and executes arbitrary OS commands as root, giving an attacker control over every mailbox, calendar and enterprise application the gateway brokers (`T1190` Exploit Public-Facing Application; `T1505.003` Web Shell post-exploitation). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 11 June and CERT-EU issued advisory 2026-008 urging immediate upgrade ([CERT-EU 2026-008, 2026-06-10](https://cert.europa.eu/publications/security-advisories/2026-008/); [BleepingComputer, 2026-06-12](https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/)). The operational driver is the confirmed in-the-wild backdooring, not any compliance date: any internet-reachable Sentry should be treated as presumed-compromised and compromise-assessed, not merely patched. Affected: Sentry ≤ R10.5.1, ≤ R10.6.1, ≤ R10.7.0; fixed in R10.5.2 / R10.6.2 / R10.7.1. See the § 0 Immediate Action callout and § 6.
