Skip to main content

Recently Exploited Palo Alto Networks CVEs

All Palo Alto Networks CVEs

15 records
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Palo Alto Networks7.896.9%KEV2026-05-13
CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Palo Alto Networks9.331.7%KEV2026-05-06
CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
Palo Alto Networks7.12.0%KEV2025-02-12
CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface
Palo Alto Networks8.898.5%KEV2025-02-12
CVE-2024-3393
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
Palo Alto Networks8.729.1%KEV2024-12-27
CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
Palo Alto Networks9.399.9%KEV2024-11-18
CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Palo Alto Networks6.994.8%KEV2024-11-18
CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
Palo Alto Networks9.299.6%KEV2024-10-09
CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
Palo Alto Networks9.998.5%KEV2024-10-09
CVE-2024-5910
Expedition: Missing Authentication Leads to Admin Account Takeover
Palo Alto Networks9.391.7%KEV2024-07-10
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
Palo Alto Networks10.0100.0%KEV2024-04-12
CVE-2022-0028
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
Palo Alto Networks8.62.5%KEV2022-08-10
CVE-2017-15944
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
-9.898.3%KEV2017-12-11
CVE-2020-2021
PAN-OS: Authentication Bypass in SAML Authentication
Palo Alto Networks10.04.4%KEV2020-06-29
CVE-2019-1579
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
-8.146.2%KEV2019-07-19

Frequently Asked Questions

How many Palo Alto Networks vulnerabilities are actively exploited?→

15 Palo Alto Networks CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-05-29.

Which Palo Alto Networks vulnerabilities are used in ransomware attacks?→

CISA marks 6 Palo Alto Networks KEV entries as known to be used in ransomware campaigns, including CVE-2026-0257, CVE-2024-0012, CVE-2024-9474, CVE-2024-3400, CVE-2020-2021.

Which Palo Alto Networks products have the most exploited vulnerabilities?→
  • +PAN-OS: 12 CVEs (12 in KEV)
  • +Expedition: 3 CVEs (3 in KEV)
Where does Palo Alto Networks publish security advisories?→

Palo Alto Networks publishes security advisories at https://security.paloaltonetworks.com/. Check the vendor advisory for fixed versions and workarounds before applying updates.

Sources

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Palo Alto Networks, MITRE, CISA, or FIRST.