CISA sets June 14 deadline for max-severity Ivanti Sentry flaw used to backdoor servers
CVE-2026-10520 is a CVSS 10.0 unauthenticated bug that hands attackers root. Researchers found at least two exposed instances already backdoored.
Federal agencies face a June 14, 2026 deadline today to patch CVE-2026-10520, a maximum-severity CVSS 10.0 flaw in Ivanti Sentry that is already being exploited to backdoor exposed servers.
Ivanti disclosed the vulnerability on June 9 in a security advisory covering two critical bugs, CVE-2026-10520 and CVE-2026-10523. The first is an unauthenticated operating-system command injection that yields root-level remote code execution with no credentials required. Ivanti Sentry, a mobile access gateway, secures traffic between corporate back-end systems and remote mobile devices, so an exposed instance is a direct route into enterprise networks.
The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on June 11 and invoked the three-day remediation window under Binding Operational Directive 26-04, setting today's deadline for civilian federal agencies. CISA's catalog now lists 35 Ivanti vulnerabilities as exploited in the wild across the company's products.
The urgency reflects how fast attackers moved: exploitation began within hours of public proof-of-concept code being released. The Shadowserver Foundation reported on June 11 that of 19 publicly reachable Sentry instances it tracked, at least two were already backdoored, and warned that all unpatched instances should be treated as compromised.
Ivanti says the flaws are fixed in versions R10.5.2, R10.6.2 and R10.7.1. Patching alone may not be enough: because exploitation is under way, administrators of any internet-facing Sentry deployment should hunt for signs of compromise rather than assume an update closes the door.
The deadline marks one of the first major enforcement events under BOD 26-04, and the narrow window underscores CISA's growing impatience with edge-device flaws that turn into mass-exploitation campaigns within days.
An entrepreneur with over a decade of experience in AI, Cloud, and HPC. He is currently a DevOps Architect and the founder of Data Phoenix, an influential media voice for the AI industry, with a strong focus on community building and open source.
More news

Public records show four MCP SSRF fixes; researcher claims fifth

Meta patches Muse setting that let local malware hijack the AI agent

CISA warns hackers are using AI coding assistants to exploit Siemens S7 controllers

Critical Splunk Enterprise flaw rated CVSS 9.8 is under active attack as CISA sets a June 21 patch deadline
Dmytro Spodarets·Jun 21, 2026