CVE-2019-11541: Ivanti Connect Secure

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

Affected products

  • Ivanti Connect Secure: version 8.2 only; version 8.3 only
  • Pulse Secure Pulse Connect Secure: version 8.2r1.0 only; version 8.2r1.1 only; version 8.2r2.0 only; version 8.2r3.0 only; version 8.2r3.1 only; version 8.2r4.0 only; …

Published 2019-04-26. Last modified 2026-06-17.