Palo Alto Networks PAN-OS 11.0
Vulnerabilities, fixed releases, vendor recommendation and support status of the 11.0 branch, from official sources.
Patcharo matches 13 vulnerabilities against Palo Alto Networks PAN-OS 11.0: 3 critical, 3 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: 11.0.6-h1. Last source modification: 4 Aug 2026.
Last verified by Patcharo: 30 Sept 2026 at 15:17 UTC
In brief
- Matched CVEs
- 13
- CISA KEV
- 3
- Newest fix stated
- 11.0.6-h1
- Support
- No statement in the catalog
- Recommended maintenance build
- No official recommendation
- Recommended release
- No official recommendation
- CERT-FR
- 7 documents
Support status
From the vendor's published life-cycle policy; support is not a recommendation.
The life-cycle policy Patcharo reads states nothing about this branch.
Vendor recommendation
The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.
Palo Alto Networks publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.
Vulnerabilities affecting 11.0
Each record matched to this branch with the fixed release the source states, newest first.
| CVE | Severity | Fixed in | Published |
|---|---|---|---|
| CVE-2025-4231 PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface | High7.2CVSS 3.1, High | 11.0.3 | |
| CVE-2025-0114 PAN-OS: Denial of Service (DoS) in GlobalProtect | High7.5CVSS 3.1, High | 11.0.2 | |
| CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | High7.2CVSS 3.1, HighKEVRansomware | 11.0.6-h1 | |
| CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) | Critical9.8CVSS 3.1, CriticalKEVRansomware | 11.0.6-h1 | |
| CVE-2024-2550 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet | High7.5CVSS 3.1, High | 11.0.6 | |
| CVE-2024-2551 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet | High7.5CVSS 3.1, High | 11.0.5 | |
| CVE-2024-9468 PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet | High7.5CVSS 3.1, High | 11.0.4-h5, 11.0.6 | |
| CVE-2024-8687 PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes | High7.1CVSS 3.1, High | 11.0.1 | |
| CVE-2024-3400 PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | Critical10CVSS 3.1, CriticalKEVRansomware | 11.0.4-h1 | |
| CVE-2024-3385 PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled | High7.5CVSS 3.1, High | 11.0.3 | |
| CVE-2024-3383 PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE) | Critical9.1CVSS 3.1, Critical | 11.0.3 | |
| CVE-2024-3382 PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets | High7.5CVSS 3.1, High | 11.0.4 | |
| CVE-2024-0008 PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface | High8.8CVSS 3.1, High | 11.0.2 |
CERT-FR advisories and alerts
Documents of the French national CERT referencing these CVEs, newest first.
- Advisory (AVI)CERTFR-2025-AVI-0505Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 12 Jun 2025
- Advisory (AVI)CERTFR-2025-AVI-0204Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 13 Mar 2025
- Advisory (AVI)CERTFR-2024-AVI-1001Vulnérabilité dans les produits Palo Alto NetworksPublished 19 Nov 2024
- Alert (ALE)CERTFR-2024-ALE-015[MàJ] Multiples vulnérabilités sur l'interface d'administration des équipements Palo Alto NetworksPublished 15 Nov 2024 · updated 27 Jan 2025 · closed 27 Jan 2025
- Advisory (AVI)CERTFR-2024-AVI-0990Vulnérabilité dans les produits Palo Alto NetworksPublished 15 Nov 2024 · updated 18 Nov 2024
- Advisory (AVI)CERTFR-2024-AVI-0986Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 14 Nov 2024
- Advisory (AVI)CERTFR-2024-AVI-0859Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 10 Oct 2024
How Patcharo reads this
Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.