The images in this article were generated with artificial intelligence. How we publish
Ivanti has published urgent patches for its Sentry safe gateway after the discovery of two critical vulnerabilities: an injection of commands into the operating system that allows remote code execution with root privileges and an authentication omission that allows for the remote creation of administrative accounts. If your organization uses Sentry (formerly MobileIron Sentry), you should treat this notice as a security priority and schedule the update to the corrected versions as soon as possible.
The failures are publicly recorded as CVE-2026-10520(OS command injection / CERs with root privileges) and CVE-2026-10523(authentication bypass that can provide administrative access). Although Ivanti reports that it has no evidence of active exploitation at the time of disclosure, recent history shows that vulnerabilities of Ivanti products have been exploited in targeted attacks and in ransomware chains, so the real risk to corporate environments is high if the devices remain ungrilled.

Ivanti has published corrective updates in the branches R10.5.2, R10.6.2 and R10.7.1; the immediate strategy should be to invent all Sentry instances, prioritize publicly exposed systems and plan patch deployments with prior tests in controlled environments. The application of the patch is the most effective mitigation but where immediate updating is not possible, implement compensatory controls: isolate the gateway from public access, restrict administrative access to safe management networks, and block ports and services that are not essential.
In addition to the patch, I recommend rotating administrative credentials, reviewing and revoking unusual accounts and keys, enabling multifactor authentication for administration access and strengthening control of access to the management console. If you detect that the application administration is accessible from the Internet, treat that as a priority for temporary mediation: limit access through access control lists (ACL), VPNs or jump hosts and monitor failed authentication attempts.
For detection and response, do not expect official indicators if Ivanti has not published IOCs: look for evidence of behavior characteristic of these vulnerabilities, such as creating unexpected administrative accounts, cron jobs or new services, shells with root privileges initiated outside the maintenance windows, processes or binary unknown in the system and outgoing suspicious connections from the gateway. Collect access records, syslog and network capture, and preserve them for forensic analysis in case of abnormal activity.
Organizations with EDR / IDS / IPS capabilities should deploy rules to alert about changes in high-privilege users, system process command execution and critical binary modification. If you have snapshots or configuration backups, create copies before applying patches to facilitate recovery. In federal and critical environments, see also the management guidelines on exploited vulnerabilities: the list of actively exploited vulnerabilities of CISA is a good reference point in priority response policies ( https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog).

Ivanti maintains a public repository with its security notices and patches; check the company's official documentation for update instructions and version notes before applying changes ( https: / / www.ivanti.com / support / security-advices). Follow the manufacturer's guidelines for roll back procedures and post-patch tests to avoid interrupting critical services.
Beyond timely repair, this incident underlines the need to improve asset governance and the patch life cycle: keep an inventory up-to-date, reduce the exposure surface (off-band management, segmentation), perform regular attack simulation exercises and review incident response processes. The link doors that mediate between mobile devices and corporate systems are high impact vectors: your commitment can open the internal network and therefore deserve preferential treatment in security programmes.
Summing up: apply patches R10.5.2 / R10.6.2 / R10.7.1 as soon as possible, temporarily isolate and protect exposed applications, audit accounts and administrative configurations, and activate specific detection for commitment indicators related to new administration, command execution and persistence. Action with speed and traceability will substantially reduce the risk of intrusion resulting in exfiltration or operational interruption.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...