Product of Ivanti

Pulse Connect Secure

As of , 7 Ivanti Pulse Connect Secure vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2019-11510.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2019-11510Arbitrary File ReadIvanti Pulse Connect SecurePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
2CVE-2020-8260Code ExecutionIvanti Pulse Connect SecurePatch this weekMetasploit module; EPSS 0.960.96
3CVE-2020-8243Code ExecutionIvanti Pulse Connect SecurePatch this weekEPSS 0.910.91
4CVE-2021-22893Use-After-FreeIvanti Pulse Connect SecurePatch this weekRansomware use0.47
5CVE-2021-22894Collaboration Suite Buffer OverflowIvanti Pulse Connect SecurePatch soon0.41
6CVE-2021-22899Command InjectionIvanti Pulse Connect SecurePatch soon0.23
7CVE-2021-22900Unrestricted File UploadIvanti Pulse Connect SecurePatch soon0.14

Added each year

24682021: 7720212022: nonenone20222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20217
2022none
2023none
2024none
2025none
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2021-22900 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  2. CVE-2021-22899 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  3. CVE-2021-22894 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  4. CVE-2021-22893 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  5. CVE-2020-8260 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  6. CVE-2020-8243 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  7. CVE-2019-11510 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.

Every change we recorded