PAN-OS vulnerabilities (CVE): affected branches, fixed releases, CISA KEV
Patcharo tracks 42 vulnerabilities matched against Palo Alto Networks PAN-OS versions: 11 critical, 10 known exploited (CISA KEV), 41 with a fixed release. Last source modification: 24 Sept 2026.
Last verified by Patcharo: 30 Sept 2026 at 12:52 UTC
Branches
Per branch: matched CVEs, CISA KEV entries, the newest fixed release stated by the vendor and the support status.
| Branch | CVEs | KEV | Newest fix stated | Support |
|---|---|---|---|---|
| 12.1 | 18 | 2 | 12.1.8 | — |
| 11.2 | 26 | 7 | 11.2.13 | — |
| 11.1 | 30 | 8 | 11.1.16-h1 | — |
| 11.0 | 13 | 3 | 11.0.6-h1 | — |
| 10.2 | 36 | 9 | 10.2.18-h8 | — |
| 10.1 | 14 | 5 | 10.1.14-h20 | — |
| 10.0 | 4 | 1 | 10.0.13 | — |
| 9.1 | 7 | 2 | 9.1.17 | — |
| 9.0 | 6 | 2 | 9.0.18 | — |
| 8.1 | 4 | 2 | 8.1.25 | — |
| 8.0 | 1 | 1 | — | — |
| 7.1 | 1 | 1 | — | — |
All PAN-OS CVEs
PAN-OS: Information Disclosure Vulnerability in URL Filtering
PAN-OSHigh7.5CVSS 3.1, High0.32%PAN-OS: IPv6 Firewall Policy Bypass
PAN-OSHigh7.2CVSS 3.1, High0.34%PAN-OS: Information Disclosure Vulnerability in Management Web Interface
PAN-OSHigh7.1CVSS 3.1, High0.28%PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
PAN-OSHigh7.2CVSS 3.1, High0.38%PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
PAN-OSCritical9.9CVSS 3.1, Critical0.47%PAN-OS: Authenticated Command Injection in CLI
PAN-OSHigh7.2CVSS 3.1, High2%PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
PAN-OSHigh7.5CVSS 3.1, High0.62%PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
PAN-OSHigh7.5CVSS 3.1, High0.83%PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
PAN-OSHigh7.2CVSS 3.1, High1%PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
PAN-OSHigh7.2CVSS 3.1, High0.26%- CVE-2026-0257KEVRansomware
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
PAN-OSCritical9.1CVSS 3.1, Critical96% PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
PAN-OSCritical9.1CVSS 3.1, Critical0.33%PAN-OS: Authenticated Admin Command Injection Vulnerability
PAN-OSHigh7.2CVSS 3.1, High1%PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
PAN-OSHigh7.5CVSS 3.1, High0.36%PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
PAN-OSCritical9.8CVSS 3.1, Critical0.37%- PAN-OSCritical9.8CVSS 3.1, Critical0.47%
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
PAN-OSHigh8.1CVSS 3.1, High1%- PAN-OSCritical9.8CVSS 3.1, Critical32%
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal
PAN-OSHigh7.5CVSS 3.1, High0.75%PAN-OS: Improper Neutralization of Input in the Management Web Interface
PAN-OSHigh7.2CVSS 3.1, High0.79%PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface
PAN-OSHigh7.2CVSS 3.1, High0.98%- PAN-OSHigh7.5CVSS 3.1, High0.42%
PAN-OS: Denial of Service (DoS) in GlobalProtect
PAN-OSHigh7.5CVSS 3.1, High0.41%PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
PAN-OSMedium6.5CVSS 3.1, Medium2%PAN-OS: Authentication Bypass in the Management Web Interface
PAN-OSCritical9.1CVSS 3.1, Critical98%PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
PAN-OSHigh7.5CVSS 3.1, High28%- CVE-2024-9474KEVRansomware
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
PAN-OSHigh7.2CVSS 3.1, High95% - CVE-2024-0012KEVRansomware
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
PAN-OSCritical9.8CVSS 3.1, Critical100% PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet
PAN-OSHigh7.5CVSS 3.1, High0.51%PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet
PAN-OSHigh7.5CVSS 3.1, High0.48%PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet
PAN-OSHigh7.5CVSS 3.1, High0.41%PAN-OS: User Impersonation in GlobalProtect Portal
PAN-OSHigh7.1CVSS 3.1, High0.32%PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes
PAN-OSHigh7.1CVSS 3.1, High0.41%PAN-OS: Command Injection Vulnerability
PAN-OSHigh7.2CVSS 3.1, High1%- CVE-2024-3400KEVRansomware
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
PAN-OSCritical10CVSS 3.1, Critical100% PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled
PAN-OSHigh7.5CVSS 3.1, High0.91%PAN-OS: Firewall Denial of Service (DoS) via Malformed NTLM Packets
PAN-OSHigh7.5CVSS 3.1, High0.89%PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)
PAN-OSCritical9.1CVSS 3.1, Critical0.58%PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets
PAN-OSHigh7.5CVSS 3.1, High0.93%PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface
PAN-OSHigh8.8CVSS 3.1, High0.50%PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
PAN-OSHigh8.6CVSS 3.1, High2%- CVE-2020-2021KEVRansomware
PAN-OS: Authentication Bypass in SAML Authentication
PAN-OSCritical10CVSS 3.1, Critical4%