CVE-2026-10520: Ivanti Sentry Unauthenticated OS Command Injection — Find Exposed Instances (opens in new tab)
Ivanti Sentry (formerly MobileIron Sentry) contains a pre-authentication OS command injection vulnerability (CVSS 10.0) allowing root-level RCE. Actively exploited, CISA KEV listed with 3-day deadline. Find exposed Sentry appliances with RECON.
Read the original article