Ivanti Sentry CVE-2026-10520 and CVE-2026-10523: Patch, Restrict, and Check WAF Coverage

Patch Ivanti Sentry CVE-2026-10520 and CVE-2026-10523, restrict appliance exposure, review admin activity, and use WAF coverage only as temporary mitigation.
Ivanti Sentry CVE-2026-10520 and CVE-2026-10523 patch checklist for exposed mobile gateway administrators

June 11, 2026 update: Ivanti Sentry CVE-2026-10520 and CVE-2026-10523 are critical gateway vulnerabilities patched in Ivanti Sentry R10.5.2, R10.6.2, and R10.7.1. BleepingComputer reports that Shadowserver is now seeing exploitation activity against internet-exposed Sentry gateways, so exposed appliances should be patched and reviewed immediately.

CISA KEV update: CISA added CVE-2026-10520 to the Known Exploited Vulnerabilities catalog on June 11, 2026, with a June 14, 2026 remediation due date for covered federal agencies. That does not change the fixed Ivanti versions, but it raises the urgency for exposed Sentry gateways and managed customer inventories.

Plain-English impact: Ivanti Sentry, formerly MobileIron Sentry, sits between mobile devices and back-end corporate systems. A compromised gateway can put mobile access, internal applications, email paths, administrator trust, and customer-facing support workflows at risk.

This is a protect-only guide. It gives administrators a safe patch, review, and communication path without publishing abuse instructions, unsafe validation steps, or implementation details.

What is affected

The CVE records list Ivanti Sentry versions before the fixed R10.5.2, R10.6.2, and R10.7.1 releases as affected. CVE-2026-10520 is rated CVSS 10 Critical in the official CVE record. CVE-2026-10523 is also critical and affects administrator trust.

  • Ivanti Sentry / MobileIron Sentry appliances on older R10.5, R10.6, or R10.7 builds.
  • Internet-exposed Sentry gateways that broker mobile-device access to internal services.
  • Hosting providers, MSPs, agencies, and IT teams that use Sentry to protect customer or staff mobile access.
  • Environments where the Sentry gateway can reach mail, identity, support, billing, CRM, file, or private application systems.

Patch priority

  1. Inventory every Sentry gateway. Include production, disaster-recovery, lab, regional, and customer-dedicated appliances.
  2. Confirm the exact branch and build. If the gateway is older than R10.5.2, R10.6.2, or R10.7.1, treat it as needing urgent maintenance.
  3. Back up before the change. Preserve configuration, certificates, integration settings, and a rollback plan according to Ivanti’s supported process.
  4. Apply the Ivanti fixed release for your branch. Use the official Ivanti advisory and release notes for the supported upgrade path.
  5. Restrict exposure while patching. Limit direct internet reachability where the business can tolerate it, especially for administrator access and management paths.
  6. Assume exposed unpatched gateways need review. Because exploitation is being reported publicly, do not stop at “patched.” Review access, logs, accounts, certificates, and downstream systems.

Post-patch verification

  • Confirm the active Sentry version shows R10.5.2, R10.6.2, R10.7.1, or a later fixed build.
  • Verify mobile-device traffic, email access, application tunnels, certificates, and identity-provider connections.
  • Check for unexpected administrator accounts, role changes, configuration edits, certificate changes, and policy changes.
  • Review gateway, authentication, mobile-device, EDR, SIEM, and firewall logs around the public patch and exploitation window.
  • Rotate credentials, tokens, or certificates if the gateway showed suspicious changes or if your incident-response team cannot rule out compromise.
  • Watch for unusual outbound connections, new scheduled tasks, changed startup behavior, unknown files, or monitoring alerts on the appliance and adjacent systems.
  • Confirm customer and staff mobile workflows after the update so support teams can separate expected post-maintenance issues from suspicious behavior.

Hosting and MSP notes

If Sentry protects access to customer-support tooling, hosting control panels, billing systems, private cloud dashboards, backup platforms, or managed email, treat this as a business-impact patch window. Customer communication should explain the maintenance window, expected reconnect behavior, and how users should report failed access or suspicious mobile prompts.

For multi-tenant environments, review tenant isolation and downstream access. A gateway that brokers access into several customer environments deserves a wider access review than a single-purpose appliance.

If you cannot patch immediately

Temporary exposure reduction is only a bridge. Restrict management access, limit trusted networks, increase logging, alert on administrator and configuration changes, and prepare an emergency maintenance window. Do not treat a firewall rule or monitoring alert as a substitute for the fixed Ivanti release.

Related Fix I.T. Phill reading

Sources

Need help planning an emergency gateway patch or reviewing access after a mobile-access appliance vulnerability? Fix I.T. Phill can help inventory exposure, coordinate a maintenance window, verify service health, and document what changed.

June 23, 2026: Cloudflare WAF coverage for Ivanti Sentry

Update note, June 24, 2026: Cloudflare’s June 23 WAF changelog lists new managed protection for Ivanti Sentry CVE-2026-10520. That helps organizations already routing Sentry traffic through Cloudflare, but it is only a mitigation layer. It does not replace the Ivanti update, exposure review, or incident checks.

CISA lists CVE-2026-10520 in the Known Exploited Vulnerabilities catalog. Treat any internet-reachable or unmanaged Sentry appliance that was not updated by the required window as a high-risk asset until it has been patched and reviewed.

The defensive path is straightforward: upgrade Ivanti Sentry to a fixed release, restrict HTTPS/admin exposure to trusted management paths, confirm the appliance is managed as intended, review administrative users and recent configuration changes, check logs for abnormal access, and coordinate mobile/email service impact before and after maintenance.

For Cloudflare users, confirm the managed ruleset is enabled for the Sentry hostname, review whether the relevant rule is in log or block mode, and watch Security Events after changing action. If you use another WAF or a hosting-provider edge, treat it as temporary virtual patching while the appliance is upgraded and validated.

Official sources: Ivanti Sentry advisory, CISA Known Exploited Vulnerabilities catalog, NVD CVE-2026-10520 entry, and Cloudflare changelog.

Picture of admin

admin

Leave a Reply

Sign up for our Newsletter

Get the latest information on what is going on in the I.T. World.