Skip to content

Palo Alto Networks PAN-OS 10.2

Vulnerabilities, fixed releases, vendor recommendation and support status of the 10.2 branch, from official sources.

Patcharo matches 36 vulnerabilities against Palo Alto Networks PAN-OS 10.2: 9 critical, 9 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: 10.2.18-h8. Last source modification: 24 Sept 2026.

Last verified by Patcharo: 30 Sept 2026 at 15:17 UTC

In brief

Matched CVEs
36
CISA KEV
9
Newest fix stated
10.2.18-h8
Support
No statement in the catalog
Recommended maintenance build
No official recommendation
Recommended release
No official recommendation
CERT-FR
16 documents

Support status

From the vendor's published life-cycle policy; support is not a recommendation.

The life-cycle policy Patcharo reads states nothing about this branch.

Vendor recommendation

The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.

Palo Alto Networks publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.

Vulnerabilities affecting 10.2

Each record matched to this branch with the fixed release the source states, newest first.

CVESeverityFixed inPublished
CVE-2026-0301

PAN-OS: Information Disclosure Vulnerability in URL Filtering

High7.5CVSS 3.1, High10.2.8
CVE-2026-0280

PAN-OS: IPv6 Firewall Policy Bypass

High7.2CVSS 3.1, High10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0281

PAN-OS: Information Disclosure Vulnerability in Management Web Interface

High7.1CVSS 3.1, High10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0283

PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)

High7.2CVSS 3.1, High10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0284

PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

Critical9.9CVSS 3.1, Critical10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0286

PAN-OS: Authenticated Command Injection in CLI

High7.2CVSS 3.1, High10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0287

PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

High7.5CVSS 3.1, High10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0288

PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

High7.5CVSS 3.1, High10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
CVE-2026-0273

PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

High7.2CVSS 3.1, High10.2.7-h35, 10.2.10-h37, 10.2.13-h22, 10.2.16-h8, 10.2.18-h7
CVE-2026-0272

PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

High7.2CVSS 3.1, High10.2.7-h35, 10.2.10-h37, 10.2.13-h22, 10.2.16-h8, 10.2.18-h5
CVE-2026-0257

PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

Critical9.1CVSS 3.1, CriticalKEVRansomware10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0258

PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching

Critical9.1CVSS 3.1, Critical10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0261

PAN-OS: Authenticated Admin Command Injection Vulnerability

High7.2CVSS 3.1, High10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0262

PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing

High7.5CVSS 3.1, High10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0264

PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

Critical9.8CVSS 3.1, Critical10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0265

PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

High8.1CVSS 3.1, High10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0300

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

Critical9.8CVSS 3.1, CriticalKEV10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
CVE-2026-0227

PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

High7.5CVSS 3.1, High10.2.7-h32, 10.2.10-h30, 10.2.13-h18, 10.2.16-h6, 10.2.18-h1
CVE-2025-4615

PAN-OS: Improper Neutralization of Input in the Management Web Interface

High7.2CVSS 3.1, High10.2.17
CVE-2025-4231

PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface

High7.2CVSS 3.1, High10.2.8
CVE-2025-0114

PAN-OS: Denial of Service (DoS) in GlobalProtect

High7.5CVSS 3.1, High10.2.5
CVE-2025-0111

PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

Medium6.5CVSS 3.1, MediumKEV10.2.7-h24, 10.2.8-h21, 10.2.9-h21, 10.2.10-h14, 10.2.11-h12, 10.2.12-h6, 10.2.13-h3
CVE-2025-0108

PAN-OS: Authentication Bypass in the Management Web Interface

Critical9.1CVSS 3.1, CriticalKEV10.2.7-h24, 10.2.8-h21, 10.2.9-h21, 10.2.10-h14, 10.2.11-h12, 10.2.12-h6, 10.2.13-h3
CVE-2024-3393

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

High7.5CVSS 3.1, HighKEV10.2.8-h19, 10.2.9-h19, 10.2.10-h12, 10.2.11-h10, 10.2.12-h4, 10.2.13-h2
CVE-2024-9474

PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

High7.2CVSS 3.1, HighKEVRansomware10.2.12-h2
CVE-2024-0012

PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

Critical9.8CVSS 3.1, CriticalKEVRansomware10.2.12-h2
CVE-2024-2550

PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet

High7.5CVSS 3.1, High10.2.11
CVE-2024-2551

PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet

High7.5CVSS 3.1, High10.2.4-h6
CVE-2024-9468

PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet

High7.5CVSS 3.1, High10.2.4-h24, 10.2.7-h24, 10.2.8-h20, 10.2.9-h11, 10.2.10-h4
CVE-2024-8687

PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes

High7.1CVSS 3.1, High10.2.4
CVE-2024-3400

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Critical10CVSS 3.1, CriticalKEVRansomware10.2.9-h1
CVE-2024-3385

PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled

High7.5CVSS 3.1, High10.2.8
CVE-2024-3383

PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)

Critical9.1CVSS 3.1, Critical10.2.5
CVE-2024-3382

PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets

High7.5CVSS 3.1, High10.2.7-h3
CVE-2024-0008

PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface

High8.8CVSS 3.1, High10.2.5
CVE-2022-0028

PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering

High8.6CVSS 3.1, HighKEV10.2.2-h2

CERT-FR advisories and alerts

Documents of the French national CERT referencing these CVEs, newest first.

  • Advisory (AVI)CERTFR-2026-AVI-1014Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 13 Aug 2026
  • Advisory (AVI)CERTFR-2026-AVI-0853Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 9 Jul 2026
  • Advisory (AVI)CERTFR-2026-AVI-0734Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 11 Jun 2026
  • Advisory (AVI)CERTFR-2026-AVI-0596Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 15 May 2026
  • Advisory (AVI)CERTFR-2026-AVI-0537Vulnérabilité dans Palo Alto Networks User-ID Authentication PortalPublished 6 May 2026
  • Advisory (AVI)CERTFR-2026-AVI-0049Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 15 Jan 2026
  • Advisory (AVI)CERTFR-2025-AVI-0856Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 9 Oct 2025
  • Advisory (AVI)CERTFR-2025-AVI-0505Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 12 Jun 2025
  • Advisory (AVI)CERTFR-2025-AVI-0204Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 13 Mar 2025
  • Advisory (AVI)CERTFR-2025-AVI-0128Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 13 Feb 2025
  • Advisory (AVI)CERTFR-2024-AVI-1107Vulnérabilité dans les produits Palo Alto NetworksPublished 27 Dec 2024
  • Advisory (AVI)CERTFR-2024-AVI-1001Vulnérabilité dans les produits Palo Alto NetworksPublished 19 Nov 2024
  • Alert (ALE)CERTFR-2024-ALE-015[MàJ] Multiples vulnérabilités sur l'interface d'administration des équipements Palo Alto NetworksPublished 15 Nov 2024 · updated 27 Jan 2025 · closed 27 Jan 2025
  • Advisory (AVI)CERTFR-2024-AVI-0990Vulnérabilité dans les produits Palo Alto NetworksPublished 15 Nov 2024 · updated 18 Nov 2024
  • Advisory (AVI)CERTFR-2024-AVI-0986Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 14 Nov 2024
  • Advisory (AVI)CERTFR-2024-AVI-0859Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 10 Oct 2024

How Patcharo reads this

Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.

Read the methodology

Other PAN-OS branches

All PAN-OS vulnerabilities and branches

Official sources