CVE-2016-3985: Pulse Secure Pulse Connect Secure

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspecified vectors.

Affected products

  • Pulse Secure Pulse Connect Secure: version 8.1r7 only; version 8.2r1 only

Published 2016-04-12. Last modified 2026-06-17.