news.mlab.sh
Back to the feed
vulnerability

CISA orders feds to patch actively exploited Ivanti flaw by Sunday

Critical
Summary

CISA has issued a Binding Operational Directive (BOD) 26-04, mandating that federal agencies patch an actively exploited vulnerability (CVE-2026-10520) in Ivanti Sentry security gateways within three days. This vulnerability, a critical OS command injection flaw, is being leveraged by attackers, and the situation highlights the urgency of patching critical security gaps. The directive underscores CISA's proactive approach to mitigating risks to the federal enterprise.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded to an actively exploited vulnerability in Ivanti Sentry, tracking CVE-2026-10520, by issuing BOD 26-04. This vulnerability, a critical OS command injection flaw within Ivanti's security gateway appliance, was discovered by Shadowserver Internet security watchdog who reported attackers had backdoored many Sentry gateways exposed online. CISA’s confirmation of active exploitation and addition to the Known Exploited Vulnerabilities Catalog (KEV) triggered the immediate directive to FCEB agencies. This action reflects a heightened concern about the potential for widespread compromise and underscores the importance of rapid patching.

Read the full article at BleepingComputer