Palo Alto Networks vulnerabilities: CVE, KEV, fixed releases
Patcharo tracks 46 vulnerabilities affecting Palo Alto Networks products: 13 critical, 13 known exploited (CISA KEV), 41 with a fixed release stated by the vendor. Last source modification: 24 Sept 2026.
Last verified by Patcharo: 30 Sept 2026 at 12:52 UTC
Products covered
Each product has its own page with affected branches and fixed releases.
- PAN-OS42 CVEs · 10 KEV
Latest vulnerabilities
Newest source publication first.
PAN-OS: Information Disclosure Vulnerability in URL Filtering
PAN-OSHigh7.5CVSS 3.1, High0.32%PAN-OS: IPv6 Firewall Policy Bypass
PAN-OSHigh7.2CVSS 3.1, High0.34%PAN-OS: Information Disclosure Vulnerability in Management Web Interface
PAN-OSHigh7.1CVSS 3.1, High0.28%PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
PAN-OSHigh7.2CVSS 3.1, High0.38%PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
PAN-OSCritical9.9CVSS 3.1, Critical0.47%PAN-OS: Authenticated Command Injection in CLI
PAN-OSHigh7.2CVSS 3.1, High2%PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
PAN-OSHigh7.5CVSS 3.1, High0.62%PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
PAN-OSHigh7.5CVSS 3.1, High0.83%PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
PAN-OSHigh7.2CVSS 3.1, High1%PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
PAN-OSHigh7.2CVSS 3.1, High0.26%
Known exploited (CISA KEV)
Vulnerabilities CISA lists as exploited, with the federal remediation due date.
- CVE-2026-0257PAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesDue 1 Jun 2026Ransomware use known
- CVE-2026-0300PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalDue 9 May 2026
- CVE-2025-0111PAN-OS: Authenticated File Read Vulnerability in the Management Web InterfaceDue 13 Mar 2025
- CVE-2025-0108PAN-OS: Authentication Bypass in the Management Web InterfaceDue 11 Mar 2025
- CVE-2024-3393PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted PacketDue 20 Jan 2025
- CVE-2024-9474PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management InterfaceDue 9 Dec 2024Ransomware use known
- CVE-2024-0012PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)Due 9 Dec 2024Ransomware use known
- CVE-2024-9465Expedition: SQL Injection Leads to Firewall Admin Credential DisclosureDue 5 Dec 2024
- CVE-2024-9463Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential DisclosureDue 5 Dec 2024
- CVE-2024-5910Expedition: Missing Authentication Leads to Admin Account TakeoverDue 28 Nov 2024