← Vulnerability feed

Vulnerability record · CVE-2021-22894 · published 27 May 2021

CVE-2021-22894: Pulse Connect Secure buffer overflow allows root code execution

Ivanti · Connect Secure

Pulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker can exploit it to execute arbitrary code as root, making it a serious risk for internet-facing VPN appliances.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 41% · top 1.4% CWE-94 · Code injectionCWE-119 · Memory buffer overflow
8.8CVSS 3.1 base score, v2 9.0
41%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a network-reachable root code execution flaw in an internet-facing VPN appliance that CISA lists as known exploited and EPSS scores above the 98th percentile.

What it is

Pulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker can exploit it to execute arbitrary code as root, making it a serious risk for internet-facing VPN appliances.

Impact

Successful exploitation gives the attacker arbitrary code execution with root privileges on the Connect Secure appliance. That level of access can expose VPN credentials, session data and the internal network the appliance protects.

Attack surface

The flaw is reached over the network (AV:N) and requires the attacker to be authenticated with low privileges (PR:L); no user interaction is needed (UI:N). It is triggered by a crafted meeting room, indicating the collaboration/meeting component is the entry point.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating real-world exploitation, and EPSS gives a 30-day probability of 0.41284 (98.6th percentile). No ransomware campaign use is documented in the record.

What to do

  • Upgrade Pulse Connect Secure to 9.1R11.4 or later as directed by the vendor advisory.
  • If immediate patching is not possible, restrict or disable the meeting room/collaboration functionality and limit authenticated access to trusted users.
  • Reduce the appliance's internet exposure where feasible and enforce strong authentication and least privilege for VPN accounts.
  • Monitor vendor guidance and CISA KEV required actions, applying the update by the stated due date.
  • After patching, rotate credentials and review appliance logs for signs of prior compromise.

Detection

  • Review Pulse Connect Secure logs for unusual meeting room creation or access activity, especially from low-privilege accounts.
  • Hunt for unexpected processes, child processes or command execution originating from the Connect Secure web/collaboration components.
  • Monitor for outbound connections or file changes on the appliance that do not match normal administrative activity.
  • Check for authentication anomalies and new or modified accounts on the appliance that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22894 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22894 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22894), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.