CVE-2021-22893

CRITICAL KEV RANSOMWARE

Pulse Connect Secure >=9.0R3/9.1R1 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-22893 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 10 public exploits from researchers including ZephrFish, orangmuda, MRLEE123456.

AI-analyzed exploit summary This repository is a honeypot (HoneyPoC) designed to deceive users into thinking it is a functional exploit for CVE-2021-22893. The script contains no actual exploit code but instead outputs misleading messages and includes a dangerous command (`rm -rvf /* --no-preserve-root`) that could cause system damage if executed.

Description

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

Exploits (10)

nomisec TROJAN 47 stars
by ZephrFish · poc
https://github.com/ZephrFish/CVE-2021-22893_HoneyPoC2

This repository is a honeypot (HoneyPoC) designed to deceive users into thinking it is a functional exploit for CVE-2021-22893. The script contains no actual exploit code but instead outputs misleading messages and includes a dangerous command (`rm -rvf /* --no-preserve-root`) that could cause system damage if executed.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec TROJAN 7 stars
by orangmuda · poc
https://github.com/orangmuda/CVE-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but contains a fake exploit script that outputs misleading messages and does not actually exploit the vulnerability. The script is deceptive and includes humorous or nonsensical content.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB
by MRLEE123456 · client-side
https://github.com/MRLEE123456/CVE-2021-22893

The repository contains only a minimal Python file and a README with a Shodan query, lacking any functional exploit code or technical details about CVE-2021-22893.

Classification
Stub 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: Pulse Connect Secure
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/thomsdev/cve-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but contains a deceptive script that simulates an exploit while actually performing harmless actions like listing directories and printing misleading messages. It includes commented-out Metasploit-like payloads and lyrics, indicating an attempt to mimic a real exploit without functional malicious code.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/rakhanobe/cve-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but is actually a fake exploit that simulates harmful actions (e.g., deleting the root filesystem) without any real exploitation logic. It includes deceptive comments and lyrics to mislead users.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/oxctdev/cve-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but contains a fake exploit script that simulates harmful actions (e.g., deleting the root filesystem) without actually exploiting the vulnerability. The script is deceptive and includes irrelevant comments about Windows XP NX bypasses, which are unrelated to the CVE.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/onsecuredev/cve-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but is actually a fake exploit that simulates harmful actions (e.g., deleting the root filesystem) without any real exploitation logic. It is designed to deceive users into believing it is functional.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/byteofjoshua/cve-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but is actually a fake exploit that simulates harmful actions (e.g., deleting the root filesystem) without any real exploitation logic. It includes deceptive comments and lyrics to mislead users.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/byteofandri/cve-2021-22893

The repository claims to be a PoC for CVE-2021-22893 but is actually a fake exploit that simulates harmful actions (e.g., deleting the root filesystem) without any real exploitation logic. It is designed to deceive users into believing it is functional.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild TROJAN
poc
https://github.com/zephrfish/cve-2021-22893

This repository is a honeypot (HoneyPoC) designed to deceive users into thinking it contains a functional exploit for CVE-2021-22893. The script contains no actual exploit code but instead performs harmless actions while pretending to execute destructive commands.

Classification
Trojan 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Pulse Secure VPN
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.9361
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-20
InTheWild.io 2021-04-28
ENISA EUVD EUVD-2021-10025
Ransomware Use Confirmed
CWE
CWE-287 CWE-416
Status published
Products (2)
ivanti/connect_secure 9.0 (13 CPE variants)
ivanti/connect_secure 9.1 (23 CPE variants)
Published Apr 23, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026