Affected Systems

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Exploitation Status

Active exploitation confirmed. Attackers targeting Internet-exposed Ivanti Sentry instances to achieve remote code execution with root privileges.

Business Impact

Maximum severity RCE vulnerability grants attackers root-level access to Ivanti Sentry gateways, enabling full system compromise, lateral movement into internal networks, data exfiltration, and potential supply chain attacks against mobile device management infrastructure. Organizations with Internet-exposed Sentry instances face immediate risk of breach.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately identify all Internet-exposed Ivanti Sentry instances and apply the latest security patch released by Ivanti
  • If patching cannot be completed within hours, isolate Ivanti Sentry systems from the Internet or shut down until patched
  • Review Sentry system logs and network traffic for indicators of compromise, focusing on unusual authentication attempts, unexpected processes, or outbound connections
  • Conduct forensic analysis on any Sentry instance that was Internet-exposed prior to patching to detect potential compromise
  • Implement network segmentation to limit Sentry gateway access and monitor all traffic to/from these systems with enhanced logging