CVE Tools

CISA orders feds to patch actively exploited Ivanti flaw by Sunday

BleepingComputerBy Sergiu Gatlan

Reported exploitedIvanti SentryMobileIron Sentry

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to patch an actively exploited Ivanti Sentry vulnerability within three days under Binding Operational Directive (BOD) 26-04. The issue, CVE-2026-10520, affects Ivanti's security gateway appliance (formerly known as MobileIron Sentry) and involves an OS command injection weakness that enables attackers to execute code. CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities (KEV) catalog after reports of widespread in-the-wild exploitation attempts, with security researchers warning that potentially unpatched systems are likely already compromised.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store