logo

CVE-2021-22893

ID: 56d882e6-3999-52cc-94fa-18800d4cc362

STIX ID: report--56d882e6-3999-52cc-94fa-18800d4cc362

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2021-05-04

Date Updated: 2026-04-26

...
...

Arctic Wolf reports that Ivanti released Pulse Connect Secure 9.1R11.4 to address a zero-day (CVE-2021-22893, CVSS 10.0) allowing unauthenticated remote code execution — observed exploited in the wild — plus three additional critical post-authentication vulnerabilities. Organizations are strongly advised to apply the 9.1R11.4 update to affected Pulse Connect Secure appliances immediately, note the upgrade is for appliances (not clients), be aware of a known certificate issue when upgrading from very old versions, and remove any previously applied workarounds after patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.