CVE-2026-10520: Ivanti Sentry — Pre-Authentication OS Command Injection (CVSS 10.0)
Ivanti — Sentry (formerly MobileIron Sentry)
A pre-authentication OS command injection in Ivanti Sentry's management interface allows remote unauthenticated attackers to execute arbitrary commands as root. CVSS 10.0. PoC public. Active backdooring confirmed by Shadowserver within 48 hours of advisory publication.