Threats
Ivanti Sentry CVE-2026-10520 Exploited in the Wild; Shadowserver Says Most Exposed Gateways Already Backdoored
Attackers are exploiting CVE-2026-10520, a max-severity OS command injection flaw in Ivanti Sentry, to run code as root on internet-exposed gateways. Shadowserver reports most exposed instances already backdoored. Patched Tuesday in R10.5.2, R10.6.2, R10.7.1 — patch now.