Vulnerability Intelligence Report
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
CVE-2021-22893
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
CISA KEV
SSVC: Active Exploitation
Automatable
Authentication Bypass
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:47.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗Improper Authentication - Generic (CWE-287)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| n/a | Pulse Connect Secure | PCS 9.0R3 or above, PCS 9.1R1 and above (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
EPSS Score
47.172%
GitHub Advisory
Vulnerability Class
Authentication Bypass
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | HackerOne · Bug Bounty Provider · USA |
| Reserved | 2021-01-06T00:00:00 |
| Published | 2021-04-23T16:29:43 |
| Last Updated | 2026-08-12T03:55:19 |
Community Chatter & Buzz