# Ivanti Sentry Under Attack: Two Critical Flaws Expose Enterprise Gateways to Root-Level Compromise
Security company Ivanti has rushed patches for two maximum-severity vulnerabilities in its Sentry secure mobile gateway—a critical piece of enterprise infrastructure that guards the boundary between corporate networks and remote mobile devices. One flaw allows unauthenticated attackers to execute arbitrary code with root privileges; the other enables complete administrative account takeover. The disclosure adds to a mounting list of Ivanti security incidents that have plagued organizations worldwide.
## The Threat
Ivanti released patches on Tuesday for two critical flaws affecting its Sentry secure mobile gateway appliance:
| Vulnerability | CVE ID | CVSS Score | Impact |
|---|---|---|---|
| OS Command Injection | CVE-2026-10520 | 9.8 (Critical) | Remote code execution as root; complete system compromise |
| Authentication Bypass | CVE-2026-10523 | 9.1 (Critical) | Unauthenticated attacker can create admin accounts and gain full administrative access |
CVE-2026-10520 stems from an OS command injection weakness that allows remote attackers—without authentication—to execute arbitrary commands with the highest privilege level on the Sentry appliance. This effectively grants attackers complete control over the gateway, enabling them to intercept, modify, or exfiltrate all traffic flowing between corporate systems and remote mobile devices.
CVE-2026-10523, the authentication bypass flaw, is equally dangerous. An unauthenticated remote attacker can exploit this vulnerability to create fraudulent administrative accounts, bypassing all authentication mechanisms. With administrative access, attackers gain complete visibility and control over the gateway's operations and configuration.
Affected versions include Sentry releases prior to R10.5.2, R10.6.2, and R10.7.1. Ivanti has confirmed that patches are available for all affected versions and urges immediate deployment.
## Background and Context
Sentry, formerly known as MobileIron Sentry, is a security gateway appliance designed to protect corporate networks by controlling and securing traffic between back-end enterprise systems and remote mobile devices. Organizations rely on it to enforce security policies, perform threat detection, and manage mobile device access to sensitive corporate resources.
Ivanti's product portfolio serves over 40,000 clients worldwide, supported by a network of more than 7,000 partners and 3,000 employees. This makes Sentry a high-value target for attackers: compromising a single Sentry appliance can expose an entire enterprise's mobile infrastructure and the sensitive data flowing through it.
The software company has faced a troubling pattern of critical vulnerabilities in recent years:
This track record suggests that attackers maintain a persistent interest in Ivanti infrastructure—and Ivanti vulnerabilities frequently become targets of opportunistic exploitation within weeks of disclosure.
## Technical Details
### CVE-2026-10520: OS Command Injection
The command injection flaw resides in how Sentry processes certain input parameters. By crafting a malicious request with specially formatted input, an attacker can break out of the intended command context and inject arbitrary shell commands. Since the Sentry service runs with root privileges (a common requirement for gateway appliances that manage network traffic), successful exploitation grants complete system access.
An attacker could:
### CVE-2026-10523: Authentication Bypass
This vulnerability appears to stem from insufficient validation of administrative credentials or session tokens. By sending a specially crafted request to the administrative interface, an unauthenticated attacker can bypass normal authentication checks and create a new administrative account.
Once administrative access is obtained, the attacker gains:
## Implications for Organizations
Immediate Risk: Organizations using affected Sentry versions are currently exposed to unauthenticated remote code execution. Unlike some vulnerabilities that require specific conditions or user interaction, these flaws can be exploited by any attacker with network access to the Sentry appliance—typically internet-facing as a gateway.
Trust Boundary Collapse: Sentry is positioned as a trust boundary device. It's meant to validate mobile devices before they connect to corporate systems. A compromised Sentry becomes an insider threat, able to approve malicious devices and expose sensitive corporate data.
Data Exposure: Mobile gateways typically handle sensitive information:
Supply Chain Considerations: Organizations that rely on Ivanti's Sentry appliances should audit their update procedures. The rapid succession of critical Ivanti vulnerabilities suggests that patch deployment cycles need to be faster than typical IT change windows.
## Recommendations
### Immediate Actions (Within 24 hours)
### Short-term (Within 1 week)
### Long-term Strategy
---
## HackWire Analysis
Why Ivanti Keeps Becoming a Target—and Why This Time Feels Different
Ivanti's Sentry vulnerabilities matter not because the company is uniquely careless, but because they're discovering flaws in a class of products that attackers care deeply about: enterprise gateway appliances that sit between internal networks and the outside world.
The pattern is telling. Over the past 18 months, Ivanti has disclosed at least seven critical vulnerabilities in core products, three of which were zero-days actively exploited before patches became available. This isn't a one-time incident recovery story—it's a persistent engineering problem that suggests insufficient secure coding practices or inadequate security testing in development pipelines.
What makes the Sentry flaws particularly concerning is the *authentication context*. CVE-2026-10523 eliminates the need for attackers to guess credentials or conduct social engineering. An unauthenticated attacker can simply create their own administrative account. Combined with CVE-2026-10520's root code execution capability, these vulnerabilities represent a complete collapse of trust in the device. An attacker doesn't need to know anything about a target organization—they can attack any Sentry appliance on the internet.
For defenders, the immediate risk is high: patches must be deployed before attackers systematically probe for unpatched instances. But the longer-term risk is strategic. Ivanti holds a dominant position in mobile device management and secure access. The frequency of critical flaws should prompt organizations to diversify their gateway architectures and reduce dependency on any single vendor's security appliances.
The timing also matters. We're five months into 2026, and we've already seen three separate waves of Ivanti patch notifications. That cadence suggests either discovery of a broader engineering problem or—more concerning—active security research specifically targeting Ivanti products, with new findings arriving faster than the company can patch.
Organizations should treat Ivanti patches with the same urgency as Windows zero-days. In many cases, Sentry is the only device standing between an attacker and complete access to mobile users' encrypted corporate traffic.
— HackWire Editorial
---
## Related Coverage