Sploitus

CVE-2026-10520

17 known exploits for CVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Affected products
Sentry
Ivanti Standalone Sentry
< 10.5.2, 10.6.2, 10.7.0
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
99.9% (100th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2026-06-09
Attack patterns
CAPEC-248
Entry point
message request body
Path
/mics/api/v2/sentry/mics-config/handleMessage
CVE-2026-10520 at NVD
Authoritative description, scoring and affected products

17 known exploits for CVE-2026-10520

Proof-of-concept code and exploit modules indexed by Sploitus