ClosedHigh impactAI Refreshed

Ivanti Patches Critical Sentry Vulnerabilities Enabling Root-Level Remote Code Execution

Occurred 10 Jun 2026·Detected 14 Jun 2026·
🇺🇸 Global — Ivanti Sentry is deployed by enterprises worldwide, primarily in the US9 reportsEnded 29 Jun 2026
CyberPropertyCyberCasualty & Liability

Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, including CVE-2026-10520, a pre-authentication OS command injection flaw enabling unauthenticated remote attackers to execute commands as root on an internet-facing perimeter appliance. CISA has added the CVE to its Known Exploited Vulnerabilities Catalog and issued a binding operational directive requiring US federal civilian agencies to patch within three days. Multiple outlets report in-the-wild exploitation within roughly 24 hours of disclosure. Vendor patches are available; the scope of compromised organisations and any named insured losses remain undisclosed.

AI-generated from linked source reports. See our correction policy.

Impact verdict

High impact. HIGH: A maximum-severity pre-authentication RCE on an internet-facing MDM/TLS perimeter gateway, with CISA-confirmed active exploitation (KEV listing) and a rare 3-day federal patch mandate, materially elevates cyber accumulation risk. Severity is bounded by uncertainty around the scope of exposed organisations, the absence of named insured losses, and the availability of vendor patches. Multi-LoB accumulation potential (cyber, tech E&O, crime) warrants active market attention.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts