Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Pulse Secure Pulse Connect Secure: Security Advisory Ivanti Connect Secure and Policy Secure (CVE-2024-37404)

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Oct 8, 2024
Added
Oct 18, 2024
Modified
Mar 26, 2026

Description

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

Solutions

pulse-secure-pulse-connect-secure-upgrade-22_7r2_2pulse-secure-pulse-connect-secure-upgrade-9_1r18_9
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.