CISA KEV adds Ivanti Sentry OS command injection — a remote unauthenticated attacker gets root-level RCE on the mobile gateway (CVE-2026-10520)
CISA catalogued an OS command-injection (CWE-78) in Ivanti Sentry (formerly MobileIron Sentry) that lets a remote unauthenticated attacker reach root-level RCE when the appliance is in an unmanaged state. Sentry brokers mobile and email access into internal systems, so a perimeter box that hands root to anyone who can reach it is initial access by design — the same shape as the Check Point IKEv1 bypass below. Apply Ivanti's fix now, confirm the appliance is not sitting in the vulnerable unmanaged state, and treat it as past-due fast: KEV due date is 2026-06-14.