Palo Alto Networks Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Palo Alto Networks products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
16
In CISA KEV
15
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Palo Alto Networks KEVs Added by Year
16 Palo Alto Networks KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-0107
Expedition: OS Command Injection Vulnerability |
Cloud NGFW, Expedition, Panorama, PAN-OS, Prisma Access | High | Not in CISA | 11 Feb 2026 |
|
CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 30 May 2026 |
|
CVE-2019-1579
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or... |
Palo Alto Networks GlobalProtect Portal/Gateway Interface | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2020-2021
PAN-OS: Authentication Bypass in SAML Authentication |
PAN-OS | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-15944
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute... |
PAN-OS | Confirmed | In CISA | 18 Aug 2022 |
|
CVE-2022-0028
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 22 Aug 2022 |
|
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect |
PAN-OS, Cloud NGFW, Prisma Access | Confirmed | In CISA | 12 Apr 2024 |
|
CVE-2024-5910
Expedition: Missing Authentication Leads to Admin Account Takeover |
Expedition | Confirmed | In CISA | 07 Nov 2024 |
|
CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure |
Expedition | Confirmed | In CISA | 14 Nov 2024 |
|
CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure |
Expedition | Confirmed | In CISA | 14 Nov 2024 |
|
CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-3393
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet |
Cloud NGFW, PAN-OS | Confirmed | In CISA | 30 Dec 2024 |
|
CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 18 Feb 2025 |
|
CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface |
Cloud NGFW, PAN-OS, Prisma Access | Confirmed | In CISA | 20 Feb 2025 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
- CWE-306 — Missing Authentication for Critical Function 3
- CWE-20 — Improper Input Validation 2
- CWE-406 — Insufficient Control of Network Message Volume (Network Amplification) 1
- CWE-565 — Reliance on Cookies without Validation and Integrity Checking 1
- CWE-73 — External Control of File Name or Path 1
- CWE-754 — Improper Check for Unusual or Exceptional Conditions 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology