CVE-2026-10520
- CVSS
- —
- EPSS
- 0.999 (100.0th percentile)
- CISA KEV
- Added 2026-06-11, due 2026-06-14
- Exploitation
- No report
- Public exploits
- 7 repositories
- State
- Unknown
Coverage

Actively exploitedCritical 100watchTowr Labs
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
Today, Ivanti published an advisory. “No way?” we hear you say. "Yes way!" Today’s advisory outlines two vulnerabilities in Ivanti’s Sentry product, appealing directly to our inner desire for sophisticated server-side, pre-authenticated vulnerabilities. CVE-2026-10520 An OS Command Injection
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev