Pulse Secure vendor intelligence
Pulse Secure Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Pulse Secure products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 9
- Known exploited vulnerabilities affecting Pulse Secure products
- In CISA KEV
- 9
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Pulse Secure KEVs with sensor-observed exploitation activity
The catalog gap matters for Pulse Secure exposure
All nine exploited Pulse Secure CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 4
- Product families
Attested Pulse Secure CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-11510
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22899
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8260
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code... |
Pulse Connect Secure / Pulse Policy Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22894
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22900
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to... |
Pulse Secure Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8243
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to... |
Pulse Connect Secre | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22893
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8218
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code... |
Pulse Connect Secure | Confirmed | In CISA | 07 Mar 2022 |
No Pulse Secure CVEs match this search or filter.
Showing 9 of 9 Pulse Secure known exploited vulnerabilities.
Recurring weakness patterns
Control, limitation, and authentication account for six mapped occurrences across this Pulse Secure KEV portfolio.
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-287
Improper Authentication
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.