CVE Intel / CVE-2019-11510

CVE-2019-11510

connect secure · ivanti
⚠
Actively exploited in the wild. Listed in the CISA Known Exploited Vulnerabilities catalogue: exploitation confirmed in the wild. Patch on priority.
CISA KEVexploited on our sensorsCritical network detectablepublic exploit: ExploitDB, Metasploit

What it is

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

Live exploitation on the huntback network (30 days)

2
attempts captured
2
distinct source IPs
2026-09-15
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.

How huntback helps

Deploy a decoy that emulates connect secure and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.

CVSSn/a Critical
EPSS1.00 (99% pct)
In CISA KEVyes
Publishedn/a
Network detectableyes, signatured
Public exploitExploitDB, Metasploit