S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 10, 2026

CVE-2026-10520 Scanner

CVE-2026-10520 Scanner - OS Command Injection vulnerability in Ivanti Sentry

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-10520
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Sentryby ivanti
R10.5.2
Updated Sep 9, 2026View on NVD →
Detail

Ivanti Sentry is a security-focused software solution used by organizations to manage and secure mobile applications and data. It is commonly deployed by IT departments in enterprises to ensure mobile policy compliance and protect sensitive information. The software serves as a secure gateway that directs authorized traffic, providing encryption and authentication mechanisms to safeguard data. Typically implemented in sectors such as finance, healthcare, and government, Ivanti Sentry aids in maintaining the integrity of mobile operations. Additionally, it integrates with various mobile device management systems, offering comprehensive management capabilities. In the cybersecurity landscape, Ivanti Sentry is a critical component for achieving robust mobile security.

The OS Command Injection vulnerability in Ivanti Sentry allows an attacker to execute arbitrary commands on the underlying operating system. An unauthenticated remote attacker could exploit this to gain root-level access, leading to a full system compromise. This vulnerability is severe as it affects versions before R10.5.2, R10.6.2, and R10.7.1. Exploitation of this vulnerability could result in unauthorized data access and manipulation. Attackers could leverage this flaw to install malware or disrupt services, posing significant risks to the affected infrastructure. Patching is crucial to mitigate the potential impacts on vulnerable installations.

The vulnerability manifests in the endpoint '/mics/api/v2/sentry/mics-config/handleMessage' where inputs are insufficiently sanitized. Attackers can inject commands via malformed messages due to improper handling of the 'message' parameter. Specifically, the failure to validate input adequately allows encapsulated command execution. This oversight permits attackers to send crafted HTTP POST requests containing payloads that trigger command execution. The vulnerability is identifiable by responses such as "Message handled successfully" indicating command processing. Due to its remote nature, the vulnerability poses a severe risk to unpatched systems.

If exploited, this vulnerability can lead to severe consequences including unauthorized access to sensitive data, manipulation or deletion of data, and potential disruption of services. The attacker could gain administrative privileges, allowing full control over the system. This might result in deploying additional malware, monitoring network traffic, or launching further attacks from the compromised system. The exploit could also damage reputations by violating data protection regulations. Timely upgrades to the latest versions are essential to prevent exploitation and safeguard the system.

REFERENCES

Solution Advice
  • Upgrade Ivanti Sentry to version R10.5.2, R10.6.2, or R10.7.1 or later.
  • Implement proper input validation and sanitization controls.
  • Regularly update all components of the Ivanti Sentry system.
  • Conduct periodic security assessments to identify and mitigate vulnerabilities.
  • Restrict network access to Ivanti Sentry to trusted sources only.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-10520 Scanner - OS Command Injection vulnerability in Ivanti Sentry | S4E