Product of Ivanti
Pulse Connect Secure
As of , 7 Ivanti Pulse Connect Secure vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2019-11510.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2019-11510Arbitrary File Read | Ivanti Pulse Connect Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 2 | CVE-2020-8260Code Execution | Ivanti Pulse Connect Secure | Patch this weekMetasploit module; EPSS 0.96 | 0.96 | ||
| 3 | CVE-2020-8243Code Execution | Ivanti Pulse Connect Secure | Patch this weekEPSS 0.91 | 0.91 | ||
| 4 | CVE-2021-22893Use-After-Free | Ivanti Pulse Connect Secure | Patch this weekRansomware use | 0.47 | ||
| 5 | CVE-2021-22894Collaboration Suite Buffer Overflow | Ivanti Pulse Connect Secure | Patch soon | 0.41 | ||
| 6 | CVE-2021-22899Command Injection | Ivanti Pulse Connect Secure | Patch soon | 0.23 | ||
| 7 | CVE-2021-22900Unrestricted File Upload | Ivanti Pulse Connect Secure | Patch soon | 0.14 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 7 |
| 2022 | none |
| 2023 | none |
| 2024 | none |
| 2025 | none |
| 2026 | none |