Security Alert: Ivanti Sentry faces two critical vulnerabilities that allow remote code execution and administrative access without authentication

Author: Published 4 min de lectura 151 reading

The images in this article were generated with artificial intelligence. How we publish

Ivanti has published urgent patches for its Sentry safe gateway after the discovery of two critical vulnerabilities: an injection of commands into the operating system that allows remote code execution with root privileges and an authentication omission that allows for the remote creation of administrative accounts. If your organization uses Sentry (formerly MobileIron Sentry), you should treat this notice as a security priority and schedule the update to the corrected versions as soon as possible.

The failures are publicly recorded as CVE-2026-10520(OS command injection / CERs with root privileges) and CVE-2026-10523(authentication bypass that can provide administrative access). Although Ivanti reports that it has no evidence of active exploitation at the time of disclosure, recent history shows that vulnerabilities of Ivanti products have been exploited in targeted attacks and in ransomware chains, so the real risk to corporate environments is high if the devices remain ungrilled.

Security Alert: Ivanti Sentry faces two critical vulnerabilities that allow remote code execution and administrative access without authentication
Image generated with IA.

Ivanti has published corrective updates in the branches R10.5.2, R10.6.2 and R10.7.1; the immediate strategy should be to invent all Sentry instances, prioritize publicly exposed systems and plan patch deployments with prior tests in controlled environments. The application of the patch is the most effective mitigation but where immediate updating is not possible, implement compensatory controls: isolate the gateway from public access, restrict administrative access to safe management networks, and block ports and services that are not essential.

In addition to the patch, I recommend rotating administrative credentials, reviewing and revoking unusual accounts and keys, enabling multifactor authentication for administration access and strengthening control of access to the management console. If you detect that the application administration is accessible from the Internet, treat that as a priority for temporary mediation: limit access through access control lists (ACL), VPNs or jump hosts and monitor failed authentication attempts.

For detection and response, do not expect official indicators if Ivanti has not published IOCs: look for evidence of behavior characteristic of these vulnerabilities, such as creating unexpected administrative accounts, cron jobs or new services, shells with root privileges initiated outside the maintenance windows, processes or binary unknown in the system and outgoing suspicious connections from the gateway. Collect access records, syslog and network capture, and preserve them for forensic analysis in case of abnormal activity.

Organizations with EDR / IDS / IPS capabilities should deploy rules to alert about changes in high-privilege users, system process command execution and critical binary modification. If you have snapshots or configuration backups, create copies before applying patches to facilitate recovery. In federal and critical environments, see also the management guidelines on exploited vulnerabilities: the list of actively exploited vulnerabilities of CISA is a good reference point in priority response policies ( https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog).

Security Alert: Ivanti Sentry faces two critical vulnerabilities that allow remote code execution and administrative access without authentication
Image generated with IA.

Ivanti maintains a public repository with its security notices and patches; check the company's official documentation for update instructions and version notes before applying changes ( https: / / www.ivanti.com / support / security-advices). Follow the manufacturer's guidelines for roll back procedures and post-patch tests to avoid interrupting critical services.

Beyond timely repair, this incident underlines the need to improve asset governance and the patch life cycle: keep an inventory up-to-date, reduce the exposure surface (off-band management, segmentation), perform regular attack simulation exercises and review incident response processes. The link doors that mediate between mobile devices and corporate systems are high impact vectors: your commitment can open the internal network and therefore deserve preferential treatment in security programmes.

Summing up: apply patches R10.5.2 / R10.6.2 / R10.7.1 as soon as possible, temporarily isolate and protect exposed applications, audit accounts and administrative configurations, and activate specific detection for commitment indicators related to new administration, command execution and persistence. Action with speed and traceability will substantially reduce the risk of intrusion resulting in exfiltration or operational interruption.

Coverage

Related

More news on the same subject.