CVE-2021-22893
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
12 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.61%
probability
This CVE has a 93.61% probability
of being exploited in the next 30 days.
0%
Top 99.8th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-284
· Improper Access Control
CWE-287
· Improper Authentication
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Exploits & PoC
ZephrFish/CVE-2021-22893_HoneyPoC2
DO NOT RUN THIS.
47
orangmuda/CVE-2021-22893
Proof On Concept — Pulse Secure CVE-2021-22893
7
MRLEE123456/CVE-2021-22893
Pulse Connect Secure RCE Vulnerability (CVE-2021-22893)
0
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
Qualys
May 11, 2021
Ivanti Connect Secure zero-days now under mass exploitation
BleepingComputer
Jan 15, 2024
Ivanti warns of Connect Secure zero-days exploited in attacks
BleepingComputer
Jan 10, 2024
Pulse Secure VPN zero-day used to hack defense firms, govt orgs
BleepingComputer
Apr 20, 2021
Pulse Secure fixes VPN zero-day used to hack high-value targets
BleepingComputer
May 03, 2021
Security Advisory 2021-021
CERT-EU
Apr 21, 2021
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Threat actors offer millions for zero-days, developers talk of exploit-as-a-service
BleepingComputer
Nov 17, 2021
CISA Alert: Top Routinely Exploited Vulnerabilities
Qualys
Jul 29, 2021
Signal Intelligence
Confidence
92%
EPSS
93.61%
Mentions
12
Last Seen
Jan 15, 2024
CNA Information
Analyst Note
CVE-2021-22893 meets zero-day criteria: official vendor description explicitly states 'This vulnerability has been exploited in the wild,' published April 2021. Articles confirm active mass exploitation of Pulse Connect Secure zero-days contemporaneously. No evidence of prior public patch availability before exploitation reports.
Triage Info
Decided atMar 05, 2026