Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, including a maximum-severity flaw that enables remote attackers to execute arbitrary code with root privileges. The issue is described as an OS command injection that can be triggered by threat actors with access to Internet-exposed Sentry instances.

While Ivanti has urged customers to apply the fixes promptly, reports differ on the level of confirmed real-world exploitation. One outlet says the vulnerability is being actively exploited in attacks, while another notes that the vulnerabilities are not known to be actively exploited, though researchers have released technical details that could help adversaries develop working exploits. A separate report states that exploitation attempts are observed in the wild and are hitting honeypots.

CVE-2026-10520 is identified in the reporting as the critical vulnerability enabling root-level remote code execution, with a second critical vulnerability also patched. Researchers have made technical information available for the earlier issue, potentially lowering the barrier for attackers to weaponize it. Administrators of Internet-facing deployments are advised to install the patches immediately to reduce exposure.