Skip to content
COOEY

EXPOSURES › CVE-2020-8260

CVE-2020-8260

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8260 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

An authenticated attacker could execute arbitrary code via uncontrolled gzip extraction in Ivanti Pulse Connect Secure.

Ivanti Pulse Connect Secure contained a code execution vulnerability allowing authenticated attackers to run arbitrary code through uncontrolled gzip extraction. This failure matters to DIB organizations because it represents an unpatched, actively exploited flaw (KEV) that could compromise secure access gateways, leading to data breaches or lateral movement. Organizations must ensure all Pulse Connect Secure instances are patched and monitored for exploitation attempts.

Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed code execution, indicating a significant gap in patch management and threat detection.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
CISA KEV listing and active exploitation indicate severe fallout, though vendor-specific press coverage is absent in the provided sources.
cooey ↗ severe-fallout -0.80
NVD entry confirms active exploitation and code execution, implying severe fallout.
"Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction."
CISA ↗ severe-fallout +0.00
No vendor-specific sentiment; CISA catalog entry only.
blog.qualys.com ↗ severe-fallout +0.00
No vendor-specific sentiment; discusses unrelated CVE-2026-68820.
sam.gov ↗ severe-fallout +0.00
No vendor-specific sentiment; procurement page only.
nypost.com ↗ severe-fallout +0.00
No vendor-specific sentiment; unrelated article.
www.cvefind.com ↗ severe-fallout +0.00
No vendor-specific sentiment; database listing only.
securityonline.info ↗ severe-fallout +0.00
No vendor-specific sentiment; discusses unrelated CVEs.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized