Ivanti Security Update – 10 June 2026

Ivanti has released a security update to fix several vulnerabilities affecting multiple versions of Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, execute arbitrary code, and gain access to the affected system.

Sample of the addressed vulnerabilities:

1. Ivanti Sentry Command Injection Vulnerability (CVE-2026-10520):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Remote Code Execution

2. Ivanti Sentry Authentication Bypass Vulnerability (CVE-2026-10523):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Bypass Security

The affected versions:

  • Ivanti Endpoint Manager Mobile 12.9.0, 12.8.0.2, 12.7.0.1, and prior.
  • Ivanti Sentry 10.5.1, 10.6.1, 10.7.0, and prior.
Vulnerabilities
  • CVE-2026-10520
  • CVE-2026-10523
  • CVE-2026-6973
  • CVE-2026-10727
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References