Ivanti Patches Critical Sentry Vulnerabilities Enabling Root-Level Remote Code Execution
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, including a maximum-severity, pre-authentication remote code execution flaw that allows root-level code execution on the appliance. Vendor patches are available; no confirmed in-the-wild exploitation or insured losses have been reported, and specific CVE identifiers, CVSS scores, and the scale of exposed organizations remain undisclosed in available reporting.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. MEDIUM: A maximum-severity, pre-authentication RCE in an enterprise gateway appliance presents meaningful cyber accumulation risk and potential claims exposure across cyber, tech E&O, and crime/fraud lines. Severity is tempered by the availability of vendor patches, the absence of confirmed exploitation, and the lack of named affected insureds. Material uncertainty persists around exposure scale, exploitation status, and specific CVE identifiers.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Intelligence ledger
Each line expands in place to its underlying sourced claim.
Known19 lines
Ivanti patched two critical vulnerabilities in Sentry secure mobile gateway▾
One vulnerability is maximum-severity and enables remote code execution with root privileges▾
Ivanti Sentry is deployed by enterprises worldwide, with primary concentration reported in the United States.▾
The affected product is published by Ivanti.▾
Ivanti disclosed and patched two critical vulnerabilities in its Sentry secure mobile gateway.▾
One of the vulnerabilities is maximum-severity, pre-authentication, and enables remote attackers to execute code with root privileges on the Sentry appliance.▾
One of the vulnerabilities is maximum-severity and enables pre-authentication remote code execution with root privileges on the Sentry appliance.▾
One vulnerability is maximum-severity, pre-authentication, and enables unauthenticated remote attackers to execute code with root privileges on the Sentry appliance.▾
Ivanti disclosed and patched two critical vulnerabilities in its Sentry secure mobile gateway.▾
No insured losses associated with the Sentry vulnerabilities have been reported.▾
No confirmed in-the-wild exploitation of the Sentry vulnerabilities has been reported.▾
Vendor patches are available for both Sentry vulnerabilities.▾
Vendor patches are available for the disclosed Sentry vulnerabilities.▾
Vendor patches have been released for both Sentry vulnerabilities.▾
The event remains at the signal lifecycle stage pending confirmed exploitation or insured loss data.▾
Vendor patches are available for the disclosed Ivanti Sentry vulnerabilities.▾
Vendor patches are available for the disclosed Sentry vulnerabilities.▾
Vendor patches addressing both Sentry vulnerabilities are available from Ivanti.▾
Vendor patches are available for both vulnerabilities; no confirmed in-the-wild exploitation has been reported as of available reporting.▾
Reported26 lines
Attackers can exploit the flaw to gain full system control on the Sentry appliance▾
Ivanti Sentry is deployed by enterprises worldwide, with reporting indicating primary deployment concentration in the United States.▾
Attackers can exploit the maximum-severity flaw to gain full system control on the Sentry appliance, with potential downstream lateral movement and data exposure.▾
Ivanti Sentry is deployed by enterprises worldwide, with primary concentration in the United States.▾
No confirmed in-the-wild exploitation of the Sentry vulnerabilities has been reported.▾
Successful exploitation could enable lateral movement and data compromise across corporate networks using Ivanti Sentry as a mobile gateway.▾
Ivanti Sentry is deployed by enterprises worldwide, with primary concentration reported in the United States.▾
Ivanti Sentry is deployed by enterprises worldwide, with primary concentration in the United States.▾
Successful exploitation could enable lateral movement and data compromise across corporate networks using Sentry as a mobile device management gateway.▾
Ivanti Sentry is deployed by enterprises worldwide, with a primary concentration in the United States.▾
One of the two vulnerabilities is maximum-severity and enables unauthenticated, pre-authentication remote code execution with root privileges on the Sentry appliance.▾
Exploitation of the maximum-severity flaw could allow attackers to gain full system control on the Sentry appliance.▾
Ivanti Sentry is deployed by enterprises worldwide, with a primary concentration in the United States, including use as a mobile device management gateway security appliance.▾
Successful exploitation could enable lateral movement and data compromise across corporate networks that rely on Sentry for mobile gateway security.▾
Ivanti Sentry is deployed by enterprises worldwide, with primary concentration reported in the United States.▾
Exploitation of the Sentry vulnerability could enable lateral movement and data compromise across corporate networks of organisations using Sentry for mobile device management gateway security.▾
Successful exploitation could give attackers full system control on the Sentry appliance, enabling lateral movement and data compromise across corporate networks.▾
One of the Sentry vulnerabilities is maximum-severity and enables unauthenticated remote code execution with root privileges on the appliance.▾
The maximum-severity flaw is exploitable pre-authentication, requiring no credentials on the Sentry appliance.▾
Successful exploitation allows attackers to gain full system control of the Sentry appliance, enabling potential lateral movement and data compromise across corporate networks.▾
No insured losses tied to the Sentry vulnerabilities have been reported.▾
No insured losses, claims, or named affected insureds have been reported in connection with the Sentry vulnerabilities.▾
No insured losses tied to the Sentry vulnerabilities have been reported in available sources.▾
Compromise of an internet-facing Sentry gateway could enable lateral movement and broader data compromise across corporate networks.▾
No confirmed in-the-wild exploitation of the Ivanti Sentry vulnerabilities has been reported in available sources.▾
No named affected insureds or insured losses have been reported in connection with the Sentry vulnerabilities.▾
Uncertain23 lines
Whether the vulnerabilities have been actively exploited in the wild prior to patching▾
Number of organizations exposed or compromised▾
Specific CVE identifiers and CVSS scores▾
The number of organizations exposed or potentially compromised is not disclosed in available reporting.▾
Specific CVSS scores for the Sentry vulnerabilities are not disclosed in available reporting beyond characterisation of one as maximum-severity.▾
Specific CVE identifiers for the Sentry vulnerabilities are not disclosed in available reporting.▾
The number of organizations exposed to or affected by the Sentry vulnerabilities is not disclosed in available reporting.▾
Specific CVE identifiers and CVSS scores for the two Sentry vulnerabilities are not present in available reporting.▾
Specific CVE identifiers and CVSS scores for the Ivanti Sentry vulnerabilities are not disclosed in available reporting.▾
The number of organisations exposed or potentially compromised via the Sentry vulnerabilities remains undisclosed in available reporting.▾
The number of organisations exposed to or affected by the disclosed Sentry vulnerabilities is not disclosed in available reporting.▾
Formal CVSS scores for the disclosed Sentry vulnerabilities have not been published in available reporting.▾
The number of organisations exposed or potentially compromised via the Sentry vulnerabilities is not disclosed in available reporting.▾
Specific CVE identifiers and CVSS scores for the Sentry vulnerabilities remain undisclosed in available reporting.▾
Whether either vulnerability has been actively exploited in the wild prior to patching is unconfirmed in available reporting.▾
Specific CVE identifiers and CVSS scores for the two vulnerabilities are not disclosed in available reporting.▾
It is not confirmed whether either vulnerability was actively exploited in the wild prior to patching.▾
Specific CVE identifiers and CVSS scores for the two disclosed vulnerabilities were not included in the available reporting.▾
Specific CVE identifiers for the Sentry vulnerabilities are not disclosed in available reporting.▾
CVSS scores for the Sentry vulnerabilities are not disclosed in available reporting.▾
No insured losses tied to the Ivanti Sentry vulnerabilities have been reported in available sources.▾
It is not publicly confirmed whether either vulnerability has been actively exploited in the wild prior to or following patching.▾
There is no confirmed evidence of in-the-wild exploitation of the Sentry vulnerabilities prior to or after disclosure in available reporting.▾
Geographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Latest developments
- Vendor confirmed patching of two critical Sentry vulnerabilities. — BleepingComputer
- Maximum-severity pre-authentication RCE with root privileges reported in Sentry. — BleepingComputer
- Reported exploitation path could yield full system control on the Sentry appliance. — BleepingComputer
- Patches available from vendor; reduces but does not eliminate exposure. — BleepingComputer
- No confirmed in-the-wild exploitation reported. — BleepingComputer
- No insured losses reported to date. — BleepingComputer
- CVE identifiers not disclosed in available reporting. — BleepingComputer
- CVSS scores not disclosed in available reporting. — BleepingComputer
Timeline
Status changed to monitoring
Auto-transitioned: no updates for 6 hours
active -> monitoring
Status changed to active
evidence_trigger: developing_promotion
developing -> active
CISA has added CVE-2026-10520, an OS command injection vulnerability in Ivanti Sentry, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The vulnerability allows total control of affected assets post-exploitation and requires federal agencies to prioritize rapid remediation under BOD 26-04. While the advisory is a routine catalog update, the critical-severity nature and confirmed active exploitation of Ivanti Sentry—a network appliance used by enterprises—carries potential cyber insurance exposure for organizations running affected versions.
Source: CISA Advisories (Official Advisory) · View source
Status changed to developing
evidence_trigger: corroboration >= 2
signal -> developing
CISA has issued its first-ever 3-day emergency patch mandate for a critical vulnerability in Ivanti Sentry (API gateway/MDM management appliance), citing confirmed active exploitation. The flaw affects federal agencies and potentially many enterprise and government customers globally. Rapid patching is required, signalling significant risk of data exposure or system compromise across organisations using the appliance.
Source: techtimes.com (Mainstream Media) · View source
Initial Detection
Ivanti has disclosed and patched two critical vulnerabilities in its Sentry secure mobile gateway, including a maximum-severity flaw allowing unauthenticated remote attackers to execute code as root. The vulnerabilities pose significant risk to enterprises using Ivanti Sentry for mobile device management gateway security, potentially enabling lateral movement and data compromise across corporate networks.
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges.
Source: BleepingComputer (Trade Media) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts