Connect Secure

Vendor:

First CVE: May 26, 2016 · Active for 10 years

131
Total CVEs
More Total CVEs than 99% of tracked products
13.1
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
10.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Connect Secure over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2016
10 years ago
Most Recent CVE
Sep 9, 2025
322 days ago

CVE Severity & Scoring

Connect Secure131 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local10 (7.6%)
Network121 (92.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low127 (96.9%)
High4 (3.1%)
Unknown0 (0.0%)
User Interaction
None109 (83.2%)
Unknown0 (0.0%)
Required22 (16.8%)
Privileges Required
Low26 (19.8%)
High47 (35.9%)
None58 (44.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (131 CVEs).

131 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows
Apr 3, 20259.899YESYES
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to p
May 8, 201910.099YESYES
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.
Jan 8, 20259.098YESYES
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att
Jan 31, 20248.298YESYES
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send special
Jan 12, 20249.198YESYES
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co
Jan 12, 20248.298YESYES
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.297YESYES
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extract
Oct 28, 20207.296YESYES
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
Sep 30, 20207.293YESNO
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration feature
Apr 23, 202110.088YESNO

Exploit Exposure

Signals from CVEs in this product scope (131 CVEs).

CISA KEV
14 CVEs
10.7% of CVEs· 98th percentile
Metasploit
8 CVEs
6.1% of CVEs· 97th percentile
Nuclei
8 CVEs
6.1% of CVEs· 97th percentile
ExploitDB
3 CVEs
2.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (131 CVEs).

Media Mentions

Signals from CVEs in this product scope (131 CVEs).

Top CNAs Publishing CVEs For Connect Secure

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1497.527.2%106
9.0158.549.0%96
8.3187.632.6%23
8.2157.838.1%22
8.1177.223.4%11
8.067.31.7%00
7.417.214.9%00
7.117.214.9%00
22.7546.75.0%23
22.6128.153.5%33
22.5107.933.0%23
22.4128.147.8%34
22.3118.038.4%33
22.2138.039.2%33
22.1147.938.9%33
21.967.735.4%11
21.1267.735.4%11