
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to remediate an actively exploited flaw in Ivanti Sentry within three days, in line with the recently released Binding Operational Directive (BOD) 26-04.
Designated as CVE-2026-10520, this critical-severity vulnerability resides in Ivanti's security gateway appliance (previously referred to as MobileIron Sentry) and originates from an OS command injection weakness.
On Wednesday, one day after Ivanti issued patches for CVE-2026-10520 and stated there was no evidence of exploitation in the wild, the Shadowserver Internet security watchdog reported that attackers had already compromised numerous Sentry gateways exposed on the internet.
Ivanti has not yet revised its advisory to indicate that CVE-2026-10520 is being actively exploited, and an Ivanti representative did not respond when contacted by BleepingComputer for additional information regarding these ongoing attacks.
Although Shadowserver now identifies just over 50 Sentry admin portals accessible online, it notes that the number of internet-exposed Ivanti Sentry instances it can detect is likely reduced due to organizations blocking its security scanner. It warns that systems not already patched are probably compromised.
"We are observing a large number of exploitation attempts targeting Ivanti Sentry CVE-2026-10520 based on the public PoC released today," the organization stated.
"While our detection numbers are relatively low because multiple Ivanti Sentry instances are unreachable in our scans (possibly blocklisted), if you have not applied the patch by now, you are most likely compromised."
On Thursday, CISA also confirmed that the CVE-2026-10520 vulnerability is now being actively exploited in attacks and added it to its Known Exploited Vulnerabilities Catalog (KEV), mandating that Federal Civilian Executive Branch (FCEB) agencies secure their Ivanti Sentry instances within three days, as stipulated by Binding Operational Directive (BOD) 26-04.
"This type of vulnerability serves as a frequent attack vector for malicious cyber actors and poses substantial risks to the federal enterprise," the cybersecurity agency warned. "Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring compliance with BOD 26-04 patching requirements."
BOD 26-04 was issued on Wednesday (replacing and revoking the earlier BOD 19-02 and BOD 22-01), and it requires U.S. federal agencies to prioritize patching if the asset is publicly exposed on the internet, if the security flaw has been added to CISA's KEV catalog, if exploitation can be automated for large-scale attacks, and if successful exploitation grants attackers partial or total control of a targeted system.
While CVE-2026-10520 is the first vulnerability to which BOD 26-04 applies, in recent weeks CISA has directed federal agencies to patch other security flaws within three days, including a Check Point VPN zero-day, a high-severity Oracle WebLogic Server vulnerability exploited in the wild, and an actively exploited cPanel plugin flaw.
Over the past several years, CISA has flagged 35 vulnerabilities across a broad range of Ivanti products that have been exploited in attacks, with 12 specifically targeted by ransomware groups.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper demonstrates how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
Max severity Ivanti Sentry vulnerability now exploited in attacks
Exploit released for Ivanti Sentry bug abused as zero-day in attacks
Ivanti warns of new actively exploited MobileIron zero-day bug
CISA orders feds to patch exploited Ivanti EPMM flaw by Saturday
CISA gives feds three days to patch Ivanti flaw exploited as zero-day