November 3, 2021 · Applied Cybernetics Group
CVE-2020-8260 — Ivanti Pulse Connect Secure
Ivanti Pulse Connect Secure Code Execution Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Ivanti
- Product
- Pulse Connect Secure
- EPSS
- 98.8th percentile (score 0.730, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-8260
CISA short description
Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
Required action
Apply updates per vendor instructions.