# CVE-2026-10520

> An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

- **CVSS:** 10 (CRITICAL)
- **EPSS:** 99.0%
- **CISA KEV:** yes
- **CWE:** CWE-78

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-10520
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
