CISA sets June 14 deadline for max-severity Ivanti Sentry flaw used to backdoor servers
CVE-2026-10520 is a CVSS 10.0 unauthenticated bug that hands attackers root. Researchers found at least two exposed instances already backdoored.
Federal agencies face a June 14, 2026 deadline today to patch CVE-2026-10520, a maximum-severity CVSS 10.0 flaw in Ivanti Sentry that is already being exploited to backdoor exposed servers.
Ivanti disclosed the vulnerability on June 9 in a security advisory covering two critical bugs, CVE-2026-10520 and CVE-2026-10523. The first is an unauthenticated operating-system command injection that yields root-level remote code execution with no credentials required. Ivanti Sentry, a mobile access gateway, secures traffic between corporate back-end systems and remote mobile devices, so an exposed instance is a direct route into enterprise networks.
The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on June 11 and invoked the three-day remediation window under Binding Operational Directive 26-04, setting today's deadline for civilian federal agencies. CISA's catalog now lists 35 Ivanti vulnerabilities as exploited in the wild across the company's products.
The urgency reflects how fast attackers moved: exploitation began within hours of public proof-of-concept code being released. The Shadowserver Foundation reported on June 11 that of 19 publicly reachable Sentry instances it tracked, at least two were already backdoored, and warned that all unpatched instances should be treated as compromised.
Ivanti says the flaws are fixed in versions R10.5.2, R10.6.2 and R10.7.1. Patching alone may not be enough: because exploitation is under way, administrators of any internet-facing Sentry deployment should hunt for signs of compromise rather than assume an update closes the door.
The deadline marks one of the first major enforcement events under BOD 26-04, and the narrow window underscores CISA's growing impatience with edge-device flaws that turn into mass-exploitation campaigns within days.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
