logo

Continued Exploitation of Pulse Secure VPN Vulnerability

ID: b6908da0-59d6-5e83-8f8b-cfb1ea32bd21

STIX ID: report--b6908da0-59d6-5e83-8f8b-cfb1ea32bd21

Feed Name: CISA Cybersecurity Advisories

Threat Score
85/100

Date Published: 2022-11-17

Date Updated: 2026-04-19

Author: CISA

...
...

CISA warns that unpatched Pulse Secure VPN servers remain widely exploitable via CVE-2019-11510, an unauthenticated arbitrary file-read vulnerability that can expose active user credentials and enable remote compromise; the advisory documents timelines of discovery and abuse (including REvil ransomware deployments and thousands of vulnerable servers), lists affected product versions, and strongly urges application of vendor patches as the primary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.