CVE-2026-10520
CRITICAL
CVSS: 10.0
EPSS: 99.9%
VulnCheck KEV
PoC Available
CWE-78
T1059
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Published: 2026-06-09