Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released.
Threat actors have started exploiting a maximum-severity OS command injection flaw in Ivanti Sentry, tracked as CVE-2026-10520, that allows remote code execution with root privileges.
“An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution ” reads the advisory.
Ivanti Sentry is a secure gateway appliance that sits between an organization’s internal systems and mobile devices, helping companies manage and protect mobile access to corporate resources.
The vulnerability affects the secure mobile gateway used to protect communications between corporate systems and mobile devices. Although Ivanti initially reported no evidence of active attacks, researchers at Shadowserver found that many internet-exposed Sentry gateways had already been backdoored shortly after the security updates were released.
“We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to @NCA_KSA for the tip!). However, all remaining likely compromised too.” the Shadowserver Foundation posted on X. “While our detection is on the lowish side due to multiple Ivanti Sentry instances not reachable in our scans (blocklisted?), if you have not patched you are most likely compromised. Vuln IP data shared in Vulnerable HTTP reporting tagged ‘cve-2026-10520′”
We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to @NCA_KSA for the tip!). However, all remaining likely compromised too. pic.twitter.com/uMgYSYLZTv
— The Shadowserver Foundation (@Shadowserver) June 10, 2026
Ivanti has not yet updated its advisory to confirm active exploitation of the issue in attacks in the wild. However, attackers frequently target Ivanti flaws because they can provide direct access into enterprise networks and enable data theft.
Threat actors can specifically target Ivanti Sentry instances mainly because they sit in a very sensitive and powerful position inside enterprise environments.
Ivanti Sentry acts as a gateway between mobile devices and internal corporate systems. That means if an attacker compromises it, they are no longer “outside” the network—they are effectively inside the trusted boundary.
Since January 2026, CISA has added multiple actively exploited Ivanti vulnerabilities to its KEV catalog, including CVE-2026-1340 affecting Endpoint Manager Mobile and CVE-2026-1603 affecting Endpoint Manager, both enabling attackers to bypass authentication or execute remote code and access sensitive enterprise systems.
The perfect robot mower for you is not nearly as fancy and feature-heavy as you may think. I’ve said it before, and I’ll say it again: it’s not the lawn mower, it’s all about the yard. A robot mower may be a market leader with top-of-the-line specs and still not be a good fit for your yard.
Here’s the great news: There’s a perfect robot mower for almost any yard. As someone who’s tested numerous types of robot lawn mowers, I’ve learned that many of the specs that brands market as groundbreaking are simply not vital for most shoppers. A mostly flat, fenced-in 0.10-acre yard doesn’t need the power that a hilly, sectioned, unfenced one-acre yard does.
A LiDAR, GPS, or wired boundary robot mower works for these yards. If you choose a wired boundary, you may have to bury wire around the flower beds, unless the borders are tall enough for the mower to avoid.
1. Don’t focus on: ‘AI-powered’ or other marketing buzzwords
Maria Diaz/ZDNET
Artificial intelligence (AI) has surpassed the popularity of acid-wash jeans in the 80s and Baby G watches in the early 2000s. And tech companies — including robot lawn mower manufacturers — are capitalizing on its appeal.
Most of these “AI-powered” or “intelligent mowing” terms are vague, geared to grab shoppers’ attention with buzzwords. That doesn’t mean that the robots don’t use AI to navigate, however.
The key is to find out how the robot uses AI to its benefit, and whether that will meet your AI expectations.
AI algorithms typically process data captured by the robot’s hardware to help it make quick decisions and adjustments. For example, a robot lawn mower may have a set of sensors and cameras to capture its surroundings. The robot’s processor then uses AI to convert that information into actionable data, so it knows whether to swerve to avoid an obstacle or slow down around a retaining wall.
Instead, look for: The navigation tech under (and on) the hood
Instead of AI and other buzzwords, you should focus on matching the robot lawn mower’s hardware and navigation system to your yard. This includes whether the robot uses RTK (Real-Time Kinematic) for positioning, and whether it features LiDAR, cameras, and sensors.
Then look at real user reviews to assess how accurately the robot mower maps and how well it performs around various types of obstacles.
There’s no blanket rule for robot mowers, but most do well with the following guidelines.
2. Don’t focus on: Premium extras
Maria Diaz/ZDNET
Skip the premium extras that don’t match your yard. You really don’t need the most advanced robot mower; you need the one that will best handle your lawn.
Most US homeowners have mostly flat lawns, simple rectangular layouts, minimal obstacles, and small yards. Yet some of the most popular mowers advertise features that don’t match this, and you don’t want to spend an extra few hundred dollars on advanced features that won’t deliver a noticeable difference in your yard.
Instead, look for: Only as much as you need
Do you have a mostly flat lawn with no fences and need a robot that can navigate to several sections separated by paths? Then you can skip AWD models and commit to superior mapping and navigation features, like multi-zone intelligence.
Similarly, if you have a yard with dense trees covering most of it, it’s safe to skip the RTK models and go for LiDAR or boundary wire options instead.
3. Don’t focus on: Flashy app features
The path lines created by the Mammotion Luba 2, as captured by our Bink Outdoor camera, is one flashy app feature I can’t quit.
Maria Diaz/ZDNET
Any dependable robot lawn mower requires an equally reliable mobile app to let you use it effectively. However, manufacturers market many flashy app features that end up being unnecessary for many users.
Don’t make app features the deciding factor unless it’s something you genuinely care about. Many users don’t rely on voice control to run their mowers and don’t mind using a separate app for their robot rather than integrating it into an existing home automation system.
A robot lawn mower with mediocre navigation and cutting performance can still have a flashy app — all while leaving behind missed patches or taking longer to finish mowing.
Instead, look for: The features you’ll actually use
Most robot mower users keep them running on a schedule to get the lawn-cutting chore off their minds. The majority of the most popular models offer basic features beyond scheduling, such as remote start and stop, basic mapping, automatic rain delay, and theft protection.
It’s easy to find robot lawn mowers with these features, but if you’re looking for anything beyond that, just be sure that the feature is worth it, especially if you’re paying extra for that model.
An example of a flashy app feature that is completely unnecessary, but I love having? The Mammotion’s pattern cutting. I can select the cutting pattern I want on the Mammotion app, whether I want lines or checkered, but I can also have the robot cut in custom patterns, like letters and numbers. I don’t care for mowed letters in my yard, but I like that it always has that freshly mowed checkered patterned with no effort from me.
4. Don’t focus on: Cutting system extras
Maria Diaz/ZDNET
The cutting width and system specs are important, as they can determine whether a robot can cover a given area in a day. However, most robot mowers use similar multiple-blade mulching systems.
Unlike traditional lawn mowers with large blades for aggressive cutting in a single pass, robot mowers typically feature a set of small blades that constantly spin. Because of this, robot mowers trim smaller amounts of grass with each pass than a traditional mower, but they also cut more frequently and leave behind smaller grass clippings that decompose naturally.
Because the robot mowers have a smaller, compounding cutting system, the real-world differences between the cutting systems from one brand to another are often smaller than you’d expect. Other issues, like poor navigation, will be glaringly obvious before small differences in blade design.
Instead, look for: Cutting width and yard size
The average US yard would benefit more from navigation quality, consistency, and connectivity than blade design. Instead, you should focus on matching the mower to your yard size.
The robot’s capacity is measured in how many acres it can cover in a day. Among other features, this is calculated based on your robot’s battery size and cutting width. Essentially, most users want a robot that can mow an entire yard in a day, so you can set it and forget it and always come home to a mowed yard. You get this by getting the appropriate robot for your yard size.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.