Skip to content

Palo Alto Networks vulnerabilities: CVE, KEV, fixed releases

Patcharo tracks 46 vulnerabilities affecting Palo Alto Networks products: 13 critical, 13 known exploited (CISA KEV), 41 with a fixed release stated by the vendor. Last source modification: 24 Sept 2026.

Last verified by Patcharo: 30 Sept 2026 at 12:52 UTC

Products covered

Each product has its own page with affected branches and fixed releases.

Latest vulnerabilities

Newest source publication first.

All Palo Alto Networks CVEs

Known exploited (CISA KEV)

Vulnerabilities CISA lists as exploited, with the federal remediation due date.

  • CVE-2026-0257PAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesDue 1 Jun 2026Ransomware use known
  • CVE-2026-0300PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalDue 9 May 2026
  • CVE-2025-0111PAN-OS: Authenticated File Read Vulnerability in the Management Web InterfaceDue 13 Mar 2025
  • CVE-2025-0108PAN-OS: Authentication Bypass in the Management Web InterfaceDue 11 Mar 2025
  • CVE-2024-3393PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted PacketDue 20 Jan 2025
  • CVE-2024-9474PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management InterfaceDue 9 Dec 2024Ransomware use known
  • CVE-2024-0012PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)Due 9 Dec 2024Ransomware use known
  • CVE-2024-9465Expedition: SQL Injection Leads to Firewall Admin Credential DisclosureDue 5 Dec 2024
  • CVE-2024-9463Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential DisclosureDue 5 Dec 2024
  • CVE-2024-5910Expedition: Missing Authentication Leads to Admin Account TakeoverDue 28 Nov 2024
Known exploited vulnerabilities (CISA KEV)

Official sources