news.mlab.sh
Back to the feed
vulnerability

Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure

Critical
Summary

A critical vulnerability (CVE-2026-10520) in Ivanti Sentry was exploited within 24 hours of its disclosure, highlighting the speed at which attackers can react to newly released vulnerabilities. The flaw, an OS command injection, allows unauthenticated remote code execution with root privileges, posing a significant risk to organizations using vulnerable versions of the Sentry mobile gateway. Rapid response and public availability of a proof-of-concept exploit accelerated the exploitation, with multiple instances already identified as compromised.

The rapid exploitation of CVE-2026-10520 in Ivanti Sentry demonstrates the importance of timely vulnerability disclosure and swift remediation. Initial reports suggested Ivanti was unaware of active exploitation, but subsequent observations from WatchTower, Rapid7, and the Shadowserver Foundation confirmed widespread attacks leveraging a publicly available proof-of-concept. Notably, attackers appeared to have pre-mapped Ivanti's asset landscape, acting quickly upon the vulnerability's release. The exploitation targeted 19 vulnerable instances, with at least two backdoored, indicating a sophisticated and immediate response from malicious actors. The fact that attackers directly targeted Ivanti's honeypots without initial system fingerprinting suggests a deliberate and well-coordinated effort. The potential impact of successful exploitation includes gaining control over configurations, stolen credentials, and access to integrated authentication systems, significantly amplifying the risk to organizations relying on Sentry for mobile device management.

Read the full article at Dark Reading