Pulse Secure SSL VPN appliances were affected by seven vulnerabilities, led by the critical pre-authentication arbitrary file-read flaw CVE-2019-11510 and authenticated administrative command injection CVE-2019-11539. The defects affected multiple Pulse Connect Secure and Pulse Policy Secure releases; Pulse Secure issued fixes on April 24, 2019, following private disclosure by DEVCORE researchers.
Public exploit availability prompted broad Internet scanning, and more than 14,500 Pulse Secure VPN endpoints were reported vulnerable to CVE-2019-11510. Researchers cited intelligence linking exploitation to a China-associated APT group and demonstrated that chaining the flaws with session-management weaknesses, SSRF, and compromised administrator credentials could yield remote code execution; organizations should urgently apply vendor patches, identify exposed appliances, rotate potentially exposed credentials, enforce MFA and client certificates where feasible, and centralize audit logging.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Thirty days after the Pulse Secure patch release, the researchers began testing Twitter's SSL VPN in a bug-bounty case study. They later reported chaining file read, session weaknesses, WebVPN SSRF, a cracked administrator credential, and CVE-2019-11539 to achieve remote code execution.
Pulse Secure released patches for the vulnerabilities reported by DEVCORE, affecting specified Pulse Connect Secure and Pulse Policy Secure versions.
DEVCORE researchers Orange Tsai and Meh Chang reported seven vulnerabilities in Pulse Secure SSL VPN products to Pulse Secure PSIRT, including the pre-authentication arbitrary file-read flaw CVE-2019-11510 and administrative command injection CVE-2019-11539.
The researchers cited intelligence indicating that an unidentified China-linked APT group was exploiting the Pulse Secure vulnerability.
Third parties released public exploits for the Pulse Secure flaws, after which the researchers observed increased botnet scanning for vulnerable systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.