[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwwSmefkBp0zhhFJt0kIyDcKQrZLP4ouCg9JDHBf3pIU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"eafd625c-5800-4b02-a671-a643a0aaac30","critical-ivanti-sentry-command-injection-vulnerability-under-active-exploitation","17e594f5-c414-48cc-b3ce-1f38bc5ef383","Critical Ivanti Sentry Command Injection Vulnerability Under Active Exploitation","CISA added CVE-2026-10520, an OS command injection vulnerability in Ivanti Sentry, to its Known Exploited Vulnerabilities catalog due to active exploitation in the wild. This vulnerability allows attackers to execute arbitrary system commands on affected devices, potentially leading to complete system compromise. The incident highlights the critical importance of maintaining current vulnerability intelligence and implementing rapid response procedures for internet-facing network appliances. Organizations must treat publicly exposed infrastructure components as high-priority targets requiring immediate attention when vulnerabilities are disclosed.","**Immediate actions:**\n- Apply security patches for Ivanti Sentry systems immediately or isolate affected devices from the network\n- Scan all internet-facing assets for the presence of vulnerable Ivanti Sentry installations\n- Monitor CISA's KEV catalog regularly for newly added vulnerabilities affecting your environment\n\n**Long-term improvements:**\n- Implement automated vulnerability scanning and patch management for all network appliances\n- Establish emergency patching procedures with defined timelines for critical and high-severity vulnerabilities\n- Maintain a comprehensive inventory of all internet-facing systems and their software versions\n\n**Detection measures:**\n- Deploy network monitoring to detect unusual command execution or lateral movement from network appliances\n- Enable logging on all network security devices to facilitate incident investigation",[12,13,14,15,16],"CIS Control 7 - Continuous Vulnerability Management","NIST SP 800-40 - Guide to Enterprise Patch Management Technologies","NIST CSF PR.IP-12 - Vulnerability Management Plan","CIS Control 1 - Inventory and Control of Enterprise Assets","CIS Control 12 - Network Infrastructure Management","published","2026-06-11T20:21:38.791314+00:00","2026-06-11T20:21:38.514+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F06\u002F11\u002Fcisa-adds-one-known-exploited-vulnerability-catalog","cisa-adds-one-known-exploited-vulnerability-to-catalog-b687e1","CISA Adds One Known Exploited Vulnerability to Catalog",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]