Updated advice on Pulse Connect Secure RCE Vulnerability
Advice for UK organisations using Pulse Connect Secure (PCS) VPN appliances.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The vendor has now provided a solution to address the PCS vulnerabilities CVE-2021-22893, CVE-2021-22894, CVE-2021-22899 and CVE-2021-22900. The solution is to upgrade the Pulse Connect Secure server software version to 9.1R.11.4.
Please see the vendor advisory for more information on how to do this. Users are required to log into the Pulse Secure portal where the upgrade is available.
Please note the vendor advice that a successful upgrade requires Pulse Connect Secure versions 9.0Rx and 9.1Rx as a pre-requisite. There is a known certificate issue for browser clients if upgrading from any version below 9.1R8. The vendor provides links to the necessary upgrades.
The NCSC strongly advises UK organisations to install the upgrade as soon as is practicable, in line with vendor guidance. This should now replace the workaround recommended previously. The vendor also advises removing this temporary mitigation and outlines how to do this.
The advice to regularly run the integrity tool checker remains the same.
FireEye published a blog saying that APT actors are actively exploiting vulnerabilities in Pulse Connect VPN appliances.
The NCSC is aware of an unauthenticated remote code execution vulnerability affecting Pulse Connect Secure (PCS) version 9.0R3 and higher (CVE-2021-22893). Pulse Secure says it recently discovered that a limited number of customers have experienced evidence of exploit behaviour on their Pulse Connect Secure (PCS) appliances.
The NCSC strongly advises UK customers using Pulse Connect Secure VPN devices to regularly run the integrity tool checker provided by the vendor. This tool checks the integrity of the complete file system and finds any additional/modified file(s). This will help identify possible activity resulting from the exploitation of Pulse Secure Connect vulnerabilities.
Organisations should note that running the integrity checker tool requires a reboot. The NCSC recommends that organisations using virtualised Pulse appliances take a snapshot of the device before running the integrity tool check. This will allow organisations to roll back to the snapshot after the tool has run, in order to conduct forensic analysis. Organisations using physical appliances should consider taking a forensic image of the device before running the tool in order to obtain the original details. Organisations should contact Ivanti for further assistance or questions.
The US Department of Homeland Security’s (DHS) Cybersecurity Infrastructure Security Agency (CISA) has published an Emergency Directive on this issue.
Affected UK organisations should report any suspected compromises to the NCSC via the website.


