CVE-2019-11510Active Exploitation(ivanti / connect_secure)

HIGHCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ivanti connect_secure systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect_secure

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 2d ago at 1 mentions (2026-02-23); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
connect_secure

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-23: 1Mentions · 2026-03-11: 1Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-02-23: 1Exploit Tool / Code · 2026-02-23: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-18: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 102-2303-1103-18
Signal classification2 categories
Active Exploitation
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-231
PoC1
2026-03-111
Active Exploitation1
2026-03-181
Active Exploitation1
Full discourse3 posts
  • Цитатник пандочки🇷🇺@DutyFrutti
    PoC

    Почему CVE-2019-11510 и CVE-2025-22457 актуальны в 2026 1. Тысячи непропатченных устройств По данным апреля 2025 года — из ~12 500 публично доступных Ivanti/Pulse серверов 66% уязвимы. Половина из них на версии 9.x, которая патчей не получит никогда. 2. EOL не означает "выключили" Организации продолжают использовать устройства после окончания поддержки годами. VPN-шлюз стоит на периметре, "работает" — никто не трогает. 3. Публичные PoC в открытом доступе 4. Лакомая цель Контроль над VPN-шлюзом = доступ во внутреннюю сеть + учётные данные всех пользователей + возможность перехвата трафика. Максимальный результат при минимальных усилиях. poc: https://github.com/sfewer-r7/CVE-2025-22457 poc2: https://github.com/lions2012/Penetration_Testing_POC/tree/main/CVE-2019-11510

    Post summary

    The post emphasizes that CVE-2019-11510 and CVE-2025-22457 remain critical due to many unpatched Ivanti/Pulse servers and publicly available PoC code, underscoring the ongoing risk of exploitation.

    00011181
    27 followersView on X
  • David@davidsheyi
    Active Exploitation

    3/ Cl0p specializes in double extortion tactics, often using phishing and exploiting CVE-2019-11510. They leak data on the dark web for extra pressure. #Cl0p #DarkWeb

    Post summary

    The tweet notes that the ransomware group Cl0p is actively exploiting CVE-2019-11510 as part of its double‑extortion campaigns.

    1000077
    555 followersView on X
  • David@davidsheyi
    Active Exploitation

    4/ Iran: Charming Kitten (APT35) focuses on critical infrastructure. They exploit VPN vulnerabilities - CVE-2019-11510. Ensure VPNs are updated. #Security #CISO

    Post summary

    Charming Kitten (APT35) reportedly exploits CVE-2019-11510 in VPNs, and users are advised to update their VPNs to mitigate the risk.

    1000031
    557 followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.2--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure8.3--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.0--

Explore more