Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Critical Vulnerabilities in Ivanti Sentry - Conflicting Assessments of Attacks

While CISA warns of active attacks on Ivanti Sentry, the company plays the threat down. Two critical flaws enable complete system compromise.

Critical vulnerabilities shake Ivanti Sentry

Two critical vulnerabilities in Ivanti's VPN gateway solution Sentry are causing considerable confusion in the IT security industry. While the US Cybersecurity and Infrastructure Security Agency (CISA) is warning of active attacks and has added the flaws to its catalog of known exploited vulnerabilities, Ivanti itself is playing down the threat situation.

Both of the vulnerabilities concerned reach the highest possible risk rating in the CVSS system. CVE-2026-10520 carries a CVSS score of 10.0 and enables attackers to inject commands into the operating system without prior authentication and to execute arbitrary code with root privileges. The second vulnerability, CVE-2026-10523 with a CVSS score of 9.9, allows authentication to be bypassed and arbitrary administrator accounts to be created.

Affected systems and available updates

The vulnerabilities affect Ivanti Sentry in versions 10.5.1, 10.6.1, 10.7.0 and earlier. The company has already provided patches: updates to versions 10.5.2, 10.6.2 and 10.7.1 close both flaws.

Particularly problematic is the fact that proof-of-concept exploits are already publicly available. The IT security researchers at watchTowr Labs have published a working exploit that demonstrates abuse of both vulnerabilities. This considerably lowers the bar for potential attackers.

Conflicting assessments of the threat situation

While several IT security firms and CISA are warning of active attacks, Ivanti maintains the position that no genuine attacks have taken place. The company's security advisory states that Ivanti is not aware of any cases of abuse prior to publication of the notice. It claims CISA added the vulnerability to the KEV catalog solely on the basis of attack attempts against honeypots.

Ivanti further argues that abuse of the more critical vulnerability CVE-2026-10520 requires access to management port 8443. Management interfaces should generally not be reachable over the internet, even if honeypots simulate such misconfigurations.

First compromises already confirmed

Ivanti's assessment is, however, likely to be out of date already. The Shadowserver Foundation reports from its network scans that of 19 vulnerable instances, at least two have already been compromised with backdoors. The researchers assume that the other instances found have since fallen victim to attackers as well.

This development underlines the urgency of the situation and contradicts the vendor's downplaying account. Researchers at Rapid7 are likewise warning of probable attacks, since several Sentry vulnerabilities have already ended up in CISA's catalog of exploited flaws in the past.

Parallel threats in other Ivanti products

In addition to the Sentry problems, further vulnerabilities have come to light in Ivanti's Endpoint Manager Mobile. These are rated as high risk and likewise require swift countermeasures by administrators.

Recommendations for administrators

Regardless of the conflicting assessments of the current threat situation, administrators should not allow themselves to be lulled by reassurances. The available updates should be installed as quickly as possible, since the vulnerabilities enable complete compromise of the affected systems.

Reviewing the network configuration is particularly important here. Even though Ivanti argues that management interfaces should not be reachable over the internet, reality shows that such misconfigurations occur frequently. Organisations should therefore ensure:

  • Immediate installation of the available patches
  • Review of network segmentation and firewall rules
  • Monitoring for suspicious activity
  • Regular security reviews of the infrastructure

Outlook and lessons

The Ivanti Sentry case illustrates the challenges involved in assessing cybersecurity threats. While vendors often tend to play down the exposure of their products, practice shows that critical vulnerabilities with publicly available exploits are quickly exploited.

The differing assessments by CISA, independent security researchers and the vendor underline the importance of gathering information from multiple sources when making security decisions. Administrators should not rely on vendor statements alone, but should also take external sources and threat intelligence into account.

It remains to be seen how the situation develops and whether further compromises come to light. The backdoor installations already confirmed, however, leave little doubt about the seriousness of the threat.