Palo Alto Networks Vulnerabilities
Palo Alto Networks builds network security products, chiefly next-generation firewalls running PAN-OS with the GlobalProtect remote access feature, and also publishes advisories for its Expedition migration tool. The database tracks 15 Palo Alto Networks CVE records. CISA lists 15 of them as exploited in the wild, most recently on 2026-05-29. The most affected products are PAN-OS, Expedition.
Recently Exploited Palo Alto Networks CVEs
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
PAN-OS: Authentication Bypass in the Management Web Interface
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
Affected Products
2 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| PAN-OS | 12 | 12 | 2026-05-29 |
| Expedition | 3 | 3 | 2024-11-14 |
Security Advisories
All Palo Alto Networks CVEs
15 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-0257 | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities | Palo Alto Networks | 7.8 | 96.9% | KEV | 2026-05-13 |
| CVE-2026-0300 | PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | Palo Alto Networks | 9.3 | 31.7% | KEV | 2026-05-06 |
| CVE-2025-0111 | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface | Palo Alto Networks | 7.1 | 2.0% | KEV | 2025-02-12 |
| CVE-2025-0108 | PAN-OS: Authentication Bypass in the Management Web Interface | Palo Alto Networks | 8.8 | 98.5% | KEV | 2025-02-12 |
| CVE-2024-3393 | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | Palo Alto Networks | 8.7 | 29.1% | KEV | 2024-12-27 |
| CVE-2024-0012 | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) | Palo Alto Networks | 9.3 | 99.9% | KEV | 2024-11-18 |
| CVE-2024-9474 | PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | Palo Alto Networks | 6.9 | 94.8% | KEV | 2024-11-18 |
| CVE-2024-9465 | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure | Palo Alto Networks | 9.2 | 99.6% | KEV | 2024-10-09 |
| CVE-2024-9463 | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure | Palo Alto Networks | 9.9 | 98.5% | KEV | 2024-10-09 |
| CVE-2024-5910 | Expedition: Missing Authentication Leads to Admin Account Takeover | Palo Alto Networks | 9.3 | 91.7% | KEV | 2024-07-10 |
| CVE-2024-3400 | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | Palo Alto Networks | 10.0 | 100.0% | KEV | 2024-04-12 |
| CVE-2022-0028 | PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering | Palo Alto Networks | 8.6 | 2.5% | KEV | 2022-08-10 |
| CVE-2017-15944 | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | - | 9.8 | 98.3% | KEV | 2017-12-11 |
| CVE-2020-2021 | PAN-OS: Authentication Bypass in SAML Authentication | Palo Alto Networks | 10.0 | 4.4% | KEV | 2020-06-29 |
| CVE-2019-1579 | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | - | 8.1 | 46.2% | KEV | 2019-07-19 |
Frequently Asked Questions
How many Palo Alto Networks vulnerabilities are actively exploited?→
15 Palo Alto Networks CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-05-29.
Which Palo Alto Networks vulnerabilities are used in ransomware attacks?→
CISA marks 6 Palo Alto Networks KEV entries as known to be used in ransomware campaigns, including CVE-2026-0257, CVE-2024-0012, CVE-2024-9474, CVE-2024-3400, CVE-2020-2021.
Which Palo Alto Networks products have the most exploited vulnerabilities?→
- +PAN-OS: 12 CVEs (12 in KEV)
- +Expedition: 3 CVEs (3 in KEV)
Where does Palo Alto Networks publish security advisories?→
Palo Alto Networks publishes security advisories at https://security.paloaltonetworks.com/. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Palo Alto Networks, MITRE, CISA, or FIRST.