CVE-2026-10520: Ivanti Sentry Unauthenticated OS Command Injection — Find Exposed Instances — RECON Blog

General News

Summary

The article details CVE-2026-10520, a critical unauthenticated OS command injection flaw in Ivanti Sentry that enables root-level remote code execution. It also references CVE-2026-10523, an authentication bypass that can let attackers create admin accounts on the same appliance. The write-up gives practical steps for locating exposed Sentry instances across perimeter networks, DNS, and TLS fingerprints. It stresses urgent remediation because the flaw is actively exploited, has a public PoC, and is already in CISA KEV. It recommends immediate patching, restricting access to the HTTPS port, and reviewing logs for signs of compromise.

Classifications

industries
Fintech & Banking
applications
Customer Service & Support

AskAI Classifications

Labels
Enterprise Software Unified Endpoint Management Security Software

Linked Companies

Ivanti
$500M to $1B
watchTowr
$1M to $5M