Palo Alto Networks vendor intelligence
Palo Alto Networks Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Palo Alto Networks products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 16
- Known exploited vulnerabilities affecting Palo Alto Networks products
- In CISA KEV
- 15
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Palo Alto Networks KEVs with sensor-observed exploitation activity
The catalog gap matters for Palo Alto Networks exposure
One of the sixteen exploited Palo Alto Networks CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 6% of this vendor portfolio.
- 94%
- Covered by CISA
- 6%
- Beyond CISA
- 7
- Product families
Attested Palo Alto Networks CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-0107
Expedition: OS Command Injection Vulnerability |
Cloud NGFW, Expedition, Panorama, PAN-OS, Prisma Access | High | Beyond CISA | 11 Feb 2026 |
|
CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 30 May 2026 |
|
CVE-2019-1579
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or... |
Palo Alto Networks GlobalProtect Portal/Gateway Interface | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2020-2021
PAN-OS: Authentication Bypass in SAML Authentication |
PAN-OS | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-15944
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute... |
PAN-OS | Confirmed | In CISA | 18 Aug 2022 |
|
CVE-2022-0028
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 22 Aug 2022 |
|
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect |
PAN-OS, Cloud NGFW, Prisma Access | Confirmed | In CISA | 12 Apr 2024 |
|
CVE-2024-5910
Expedition: Missing Authentication Leads to Admin Account Takeover |
Expedition | Confirmed | In CISA | 07 Nov 2024 |
|
CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure |
Expedition | Confirmed | In CISA | 14 Nov 2024 |
|
CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure |
Expedition | Confirmed | In CISA | 14 Nov 2024 |
|
CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-3393
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet |
Cloud NGFW, PAN-OS | Confirmed | In CISA | 30 Dec 2024 |
|
CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 18 Feb 2025 |
|
CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 20 Feb 2025 |
No Palo Alto Networks CVEs match this search or filter.
Showing 16 of 16 Palo Alto Networks known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, missing authentication for critical function, and input validation account for eight mapped occurrences across this Palo Alto Networks KEV portfolio.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-306
Missing Authentication for Critical Function
CWE-20
Improper Input Validation
CWE-406
Insufficient Control of Network Message Volume (Network Amplification)
CWE-565
Reliance on Cookies without Validation and Integrity Checking
CWE-73
External Control of File Name or Path
CWE-754
Improper Check for Unusual or Exceptional Conditions
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.