CVE-2026-10520
CISA KEVAs of 2026-06-12, CVE-2026-10520 is a CVSS 10 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited); Public exploit code available; Nuclei detection template exists. EPSS exploitation probability 99.0%. Threadlinqs Intelligence tracks 5 threats exploiting it.
Last updated: 2026-06-12
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-78
Exploitation status
CISA KEV-listed (known exploited) · public exploit code available · nuclei detection template exists
- watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 (github)
- 0xBlackash/CVE-2026-10520 (github)
- HORKimhab/CVE-2026-10520-10523 (github)
- error-inside/CVE-2026-10520 (github)
- emilliewatson96/spryCVE-2026-10520 (github)
Threats tracking this CVE
- CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB Agencies — MEDIUM
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2 — HIGH
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers — HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers — HIGH
- CVE-2026-10520 — Ivanti Sentry Unauthenticated OS Command Injection (Root RCE), added to CISA KEV — CRITICAL
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.