← Vulnerability feed

Vulnerability record · CVE-2021-22893 · published 23 April 2021

CVE-2021-22893: Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCE

Ivanti · Connect Secure

Pulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collaboration features, combined with a use-after-free condition. An unauthenticated remote attacker can exploit this to execute arbitrary code on the gateway, which is a critical edge device controlling remote access.

10.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 47% · top 1.2% CWE-287 · Improper authenticationCWE-416 · Use after free
10.0CVSS 3.1 base score, v2 7.5
47%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
10References
12 Aug 2026Last modified by NVD

Description

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated remote code execution, active exploitation in the wild, and known ransomware use make this an urgent risk.

What it is

Pulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collaboration features, combined with a use-after-free condition. An unauthenticated remote attacker can exploit this to execute arbitrary code on the gateway, which is a critical edge device controlling remote access.

Impact

An attacker gains unauthenticated remote code execution on the Pulse Connect Secure gateway, allowing full compromise of the appliance and potentially the internal network it protects. This can lead to credential theft, lateral movement, and persistent access.

Attack surface

The vulnerability is reachable over the network via the Windows File Share Browser and Pulse Secure Collaboration features, requiring no authentication and no user interaction. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.

Exploitation

The vulnerability has been exploited in the wild, is listed in CISA KEV with known ransomware campaign use, and has a high EPSS probability (0.47172, 98.774th percentile).

What to do

  • Apply the vendor security update for Pulse Connect Secure as instructed in the vendor advisory (SA44784) immediately.
  • If patching is not immediately possible, disable the Windows File Share Browser and Pulse Secure Collaboration features or apply the vendor-provided mitigation.
  • Isolate or restrict network access to the Pulse Connect Secure gateway to trusted sources only.
  • Monitor for and investigate any signs of compromise, and reset credentials and certificates if compromise is suspected.
  • Review CISA KEV guidance and ensure the due date (2022-05-03) is met.

Detection

  • Monitor Pulse Connect Secure logs for unusual authentication bypass attempts or access to the Windows File Share Browser and Collaboration features.
  • Hunt for unexpected processes, files, or network connections on the Pulse Connect Secure appliance.
  • Use the FireEye threat research indicators to detect known exploitation activity.
  • Check for unauthorized configuration changes or new administrative accounts on the gateway.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22893 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Use-After-Free Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22893 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22893), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.