CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 100% chance of exploitation in the next 30 days.

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

Affected products

  • Ivanti Connect Secure: version 8.2 only; version 8.3 only; version 9.0 only

Published 2019-05-08. Last modified 2026-06-17.