November 3, 2021 · Applied Cybernetics Group
CVE-2019-11539 — Ivanti Pulse Connect Secure and Pulse Policy Secure
known ransomware use
Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Ivanti
- Product
- Pulse Connect Secure and Pulse Policy Secure
- EPSS
- 99.9th percentile (score 0.939, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-11539
CISA short description
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
Required action
Apply updates per vendor instructions.