Palo Alto Networks PAN-OS
Our sources currently list 234 known vulnerabilities affecting Palo Alto Networks PAN-OS. 37 are rated critical severity. 14 of 234 are actively exploited according to CISA, the most recent added 29 May 2026.
Last updated: 22 July 2026, 20:43 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2024-3400 | Critical (10.0) | Actively exploited · ransomware | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinc… | |
| CVE-2024-0012 | Critical (9.8) | Actively exploited · ransomware | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator … | |
| CVE-2025-0108 | Critical (9.1) | Actively exploited | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authenticat… | |
| CVE-2017-15944 | Critical (9.8) | Actively exploited | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving th… | |
| CVE-2024-9474 | High (7.2) | Actively exploited · ransomware | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firew… | |
| CVE-2026-0257 | Critical (9.1) | Actively exploited · ransomware | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establi… | |
| CVE-2016-5195 | High (7.0) | Actively exploited | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature … | |
| CVE-2019-1579 | High (8.1) | Actively exploited · ransomware | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled … | |
| CVE-2026-0300 | Critical (9.8) | Actively exploited | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execu… | |
| CVE-2024-3393 | High (7.5) | Actively exploited | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data p… | |
| CVE-2018-14634 | High (7.8) | Actively exploited | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use thi… | |
| CVE-2020-2021 | Critical (10.0) | Actively exploited · ransomware | When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of s… | |
| CVE-2022-0028 | High (8.6) | Actively exploited | A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would ap… | |
| CVE-2025-0111 | Medium (6.5) | Actively exploited | An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read fil… | |
| CVE-2020-2038 | High (7.2) | Elevated likelihood (86%) | An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue … | |
| CVE-2020-2039 | Medium (5.3) | Elevated likelihood (46%) | An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interf… | |
| CVE-2016-4971 | High (8.8) | Elevated likelihood (46%) | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource. | |
| CVE-2016-8610 | High (7.5) | Elevated likelihood (40%) | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection … | |
| CVE-2016-9150 | Critical (9.8) | Elevated likelihood (35%) | Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and … | |
| CVE-2021-3060 | High (8.1) | Elevated likelihood (34%) | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific… | |
| CVE-2020-2036 | High (8.8) | Elevated likelihood (24%) | A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrator with an active authenticated… | |
| CVE-2021-3064 | Critical (9.8) | Elevated likelihood (19%) | A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system … | |
| CVE-2018-18065 | Medium (6.5) | Elevated likelihood (17%) | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to … | |
| CVE-2019-1559 | Medium (5.9) | Elevated likelihood (17%) | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently … | |
| CVE-2020-2034 | High (8.1) | No exploitation reported | An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An … | |
| CVE-2017-8390 | Critical (9.8) | No exploitation reported | The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a craft… | |
| CVE-2017-15940 | Critical (9.8) | No exploitation reported | The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote aut… | |
| CVE-2016-3657 | Critical (9.8) | No exploitation reported | Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to … | |
| CVE-2012-6603 | Critical (10.0) | No exploitation reported | The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administra… | |
| CVE-2012-6601 | Critical (10.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary co… | |
| CVE-2012-6592 | Critical (10.0) | No exploitation reported | Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091. | |
| CVE-2012-6593 | Critical (10.0) | No exploitation reported | Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088. | |
| CVE-2020-2040 | Critical (9.8) | No exploitation reported | A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a ma… | |
| CVE-2018-10141 | Medium (6.1) | No exploitation reported | GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML. | |
| CVE-2020-2037 | High (7.2) | No exploitation reported | An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue … | |
| CVE-2020-1992 | High (8.1) | No exploitation reported | A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a deni… | |
| CVE-2019-1581 | Critical (9.8) | No exploitation reported | A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interfac… | |
| CVE-2020-2000 | High (7.2) | No exploitation reported | An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentia… | |
| CVE-2019-1580 | Critical (9.8) | No exploitation reported | Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft… | |
| CVE-2012-6604 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspe… | |
| CVE-2012-6605 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspe… | |
| CVE-2016-3655 | Critical (9.8) | No exploitation reported | The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitra… | |
| CVE-2012-6600 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands … | |
| CVE-2012-6591 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary comma… | |
| CVE-2012-6594 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to ex… | |
| CVE-2012-6595 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary … | |
| CVE-2012-6598 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors… | |
| CVE-2012-6599 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands … | |
| CVE-2012-6602 | Critical (9.0) | No exploitation reported | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via u… | |
| CVE-2015-6531 | High (7.8) | No exploitation reported | Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file. |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
14 of these are being actively exploited right now.
Our Newcastle team can audit your Palo Alto Networks estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
