CVE-2019-11510

ENISA EUVD: EUVD-2019-3183 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 12 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.46%
probability
This CVE has a 94.46% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.0

Source: NVD
9.9
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N

Affected Products

Attack Intelligence

Exploits & PoC

projectzeroindia/CVE-2019-11510

Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)

363
BishopFox/pwn-pulse

Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)

134
imjdl/CVE-2019-11510-poc

Pulse Secure SSL VPN pre-auth file reading

50
cisagov/check-your-pulse

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

28
aqhmal/pulsexploit

Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this s

9
es0/CVE-2019-11510_poc

PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability

5
andripwn/pulse-exploit

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

1
8 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
75%
EPSS 94.46%
CVSS v3.0 9.9
Mentions 12
Last Seen May 08, 2025

CNA Information

Analyst Note

CVE-2019-11510 is identified as a Pulse Secure VPN zero-day in BleepingComputer reporting active exploitation against defense firms and government organizations. The 2019 publication year combined with explicit zero-day designation and documented in-the-wild attacks meets zero-day criteria, though specific patch timing details are unavailable.

Threat Actors 14

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Kinsing
apt_group 🇷🇺 RU
TeamTNT
apt_group 🇩🇪 DE
Cuboid Sandstorm
apt_group 🇮🇷 IR
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
Gray Sandstorm
apt_group 🇮🇷 IR
Bitwise Spider
apt_group Financial gain 🇷🇺 RU
WOLF SPIDER
apt_group Financial crime 🇷🇴 RO
Scarred Manticore
apt_group Information theft and espionage 🇮🇷 IR

Triage Info

Decided atMar 20, 2026