CVE-2026-10520: Ivanti Sentry Unauthenticated OS Command Injection — Find Exposed Instances — RECON Blog
Summary
The article details CVE-2026-10520, a critical unauthenticated OS command injection flaw in Ivanti Sentry that enables root-level remote code execution. It also references CVE-2026-10523, an authentication bypass that can let attackers create admin accounts on the same appliance. The write-up gives practical steps for locating exposed Sentry instances across perimeter networks, DNS, and TLS fingerprints. It stresses urgent remediation because the flaw is actively exploited, has a public PoC, and is already in CISA KEV. It recommends immediate patching, restricting access to the HTTPS port, and reviewing logs for signs of compromise.
Classifications
industries
Fintech & Banking
applications
Customer Service & Support
AskAI Classifications
Labels
Enterprise Software
Unified Endpoint Management
Security Software