June 11, 2026 — CISA confirmed active exploitation of a maximum-severity vulnerability in Ivanti’s Sentry gateway appliance and added it to its Known Exploited Vulnerabilities catalog, triggering a new binding patch deadline for federal agencies.
What happened
The flaw, an OS command-injection weakness in Ivanti’s security gateway appliance formerly known as MobileIron Sentry, was confirmed as actively exploited and catalogued by CISA. Under newly issued Binding Operational Directive 26-04, CISA ordered federal civilian agencies to patch the flaw within three days.
Why it matters
A three-day emergency patch window for a maximum-severity, actively exploited edge-appliance vulnerability underscores how little time defenders now have between public disclosure and mandated remediation for internet-facing management infrastructure.
Security and infrastructure impact
Organizations running Ivanti gateway appliances outside the federal directive’s direct scope should still treat the finding as an urgent patch signal, given that KEV entries reliably indicate active, opportunistic exploitation rather than theoretical risk.

Leave a Reply