CVE-2026-10520
KEV Critical · CVSS 10.0Ivanti Sentry — OS Command Injection RCE
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- Listed
- 2026-06-11
- Class
- other
- CWE-78
Description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Search profile — drives PoC discovery
Symbols CVE-2026-10520CVE-2026-10523watchTowr-vs-Ivanti-Sentry-RCEwatchtowrlabsroot-level RCEunauthenticated
Keywords CVE-2026-10520CVE-2026-10523Ivanti Sentry RCEIvanti Sentry OS command injectionIvanti Sentry unauthenticated RCEwatchTowr Ivanti SentryIvanti Sentry R10.5.2 R10.6.2 R10.7.1Sentry root RCE PoCwatchtowrlabs Sentry exploit
Versions: before R10.5.2, R10.6.2, R10.7.1
Ranked PoCs (5) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 12known researcher · cited in references · recent activitygh_search · Python
- ★ 2
- ★ 0
- ★ 4
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-06-12T18:00:30.000Z · profiled 2026-06-16T18:19:23.017Z