Palo Alto Networks Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Palo Alto Networks products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

16

In CISA KEV

15

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Palo Alto Networks KEVs Added by Year

Loading...

16 Palo Alto Networks KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-0107

Expedition: OS Command Injection Vulnerability

High Not in CISA 11 Feb 2026
CVE-2026-0300

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

Confirmed In CISA 01 Jun 2026
CVE-2026-0257

PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

Confirmed In CISA 30 May 2026
CVE-2019-1579

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or...

Confirmed In CISA 10 Jan 2022
CVE-2020-2021

PAN-OS: Authentication Bypass in SAML Authentication

Confirmed In CISA 25 Mar 2022
CVE-2017-15944

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute...

Confirmed In CISA 18 Aug 2022
CVE-2022-0028

PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering

Confirmed In CISA 22 Aug 2022
CVE-2024-3400

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Confirmed In CISA 12 Apr 2024
CVE-2024-5910

Expedition: Missing Authentication Leads to Admin Account Takeover

Confirmed In CISA 07 Nov 2024
CVE-2024-9463

Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure

Confirmed In CISA 14 Nov 2024
CVE-2024-9465

Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure

Confirmed In CISA 14 Nov 2024
CVE-2024-0012

PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

Confirmed In CISA 18 Nov 2024
CVE-2024-9474

PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

Confirmed In CISA 18 Nov 2024
CVE-2024-3393

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

Confirmed In CISA 30 Dec 2024
CVE-2025-0108

PAN-OS: Authentication Bypass in the Management Web Interface

Confirmed In CISA 18 Feb 2025
CVE-2025-0111

PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

Confirmed In CISA 20 Feb 2025

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
  • CWE-306 — Missing Authentication for Critical Function 3
  • CWE-20 — Improper Input Validation 2
  • CWE-406 — Insufficient Control of Network Message Volume (Network Amplification) 1
  • CWE-565 — Reliance on Cookies without Validation and Integrity Checking 1
  • CWE-73 — External Control of File Name or Path 1
  • CWE-754 — Improper Check for Unusual or Exceptional Conditions 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology