Connect Secure
Vendor:
First CVE: May 26, 2016 · Active for 10 years
131
Total CVEs
More Total CVEs than 99% of tracked products
13.1
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
10.7%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Connect Secure over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2016
10 years ago
Most Recent CVE
Sep 9, 2025
322 days ago
CVE Severity & Scoring
Connect Secure131 CVEs
35%
52%
11%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (7.6%)
Network121 (92.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low127 (96.9%)
High4 (3.1%)
Unknown0 (0.0%)
User Interaction
None109 (83.2%)
Unknown0 (0.0%)
Required22 (16.8%)
Privileges Required
Low26 (19.8%)
High47 (35.9%)
None58 (44.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (131 CVEs).
131 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-22457CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows | Apr 3, 2025 | 9.8 | 99 | YES | YES |
CVE-2019-11510CRITICAL In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to p | May 8, 2019 | 10.0 | 99 | YES | YES |
CVE-2025-0282CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22. | Jan 8, 2025 | 9.0 | 98 | YES | YES |
CVE-2024-21893HIGH A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att | Jan 31, 2024 | 8.2 | 98 | YES | YES |
CVE-2024-21887CRITICAL A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send special | Jan 12, 2024 | 9.1 | 98 | YES | YES |
CVE-2023-46805HIGH An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co | Jan 12, 2024 | 8.2 | 98 | YES | YES |
CVE-2019-11539HIGH In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo | Apr 26, 2019 | 7.2 | 97 | YES | YES |
CVE-2020-8260HIGH A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extract | Oct 28, 2020 | 7.2 | 96 | YES | YES |
CVE-2020-8243HIGH A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution. | Sep 30, 2020 | 7.2 | 93 | YES | NO |
CVE-2021-22893CRITICAL Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration feature | Apr 23, 2021 | 10.0 | 88 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (131 CVEs).
CISA KEV
14 CVEs
10.7% of CVEs· 98th percentile
Metasploit
8 CVEs
6.1% of CVEs· 97th percentile
Nuclei
8 CVEs
6.1% of CVEs· 97th percentile
ExploitDB
3 CVEs
2.3% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (131 CVEs).
Media Mentions
Signals from CVEs in this product scope (131 CVEs).
Top CNAs Publishing CVEs For Connect Secure
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 49 | 7.5 | 27.2% | 10 | 6 |
| 9.0 | 15 | 8.5 | 49.0% | 9 | 6 |
| 8.3 | 18 | 7.6 | 32.6% | 2 | 3 |
| 8.2 | 15 | 7.8 | 38.1% | 2 | 2 |
| 8.1 | 17 | 7.2 | 23.4% | 1 | 1 |
| 8.0 | 6 | 7.3 | 1.7% | 0 | 0 |
| 7.4 | 1 | 7.2 | 14.9% | 0 | 0 |
| 7.1 | 1 | 7.2 | 14.9% | 0 | 0 |
| 22.7 | 54 | 6.7 | 5.0% | 2 | 3 |
| 22.6 | 12 | 8.1 | 53.5% | 3 | 3 |
| 22.5 | 10 | 7.9 | 33.0% | 2 | 3 |
| 22.4 | 12 | 8.1 | 47.8% | 3 | 4 |
| 22.3 | 11 | 8.0 | 38.4% | 3 | 3 |
| 22.2 | 13 | 8.0 | 39.2% | 3 | 3 |
| 22.1 | 14 | 7.9 | 38.9% | 3 | 3 |
| 21.9 | 6 | 7.7 | 35.4% | 1 | 1 |
| 21.12 | 6 | 7.7 | 35.4% | 1 | 1 |