
Patch tonight: CVE-2026-10520 is a CVSS 10 pre-auth root shell on Ivanti Sentry
CVE-2026-10520 is a CVSS 10.0, EPSS 0.99, KEV-listed OS command injection in Ivanti Standalone Sentry that gives unauthenticated attackers root. There is no workaround — here is the fix path, the attack chain, and the honest status of public exploit code.
















