CVE-2018-5299: Pulse Secure Pulse Connect Secure

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (PPS) before 5.4R4, leading to memory corruption and possibly remote code execution.

Affected products

  • Pulse Secure Pulse Connect Secure: from 8.3r1, up to and including 8.3r3
  • Pulse Secure Pulse Policy Secure: from 5.4r1, up to and including 5.4r3

Published 2018-01-16. Last modified 2026-06-17.