Paloaltonetworks Security Vulnerabilities (CVEs)

Track 49 security vulnerabilities affecting Paloaltonetworks products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

11 Critical
26 High
11 Medium
1 Low
🔔 Get Alerts for Paloaltonetworks
CVE-2026-0227 7.5

An unauthenticated attacker can send specially crafted requests to Palo Alto Networks PAN-OS firewalls, causing them to crash and enter maintenance mo...

Jan 15, 2026
CVE-2025-4614 2.7

An authenticated administrator in Palo Alto Networks PAN-OS software can view session tokens of users logged into the firewall web UI, potentially ena...

Oct 9, 2025
CVE-2025-4615 7.2

An authenticated administrator can bypass system restrictions in Palo Alto Networks PAN-OS management web interface to execute arbitrary commands. Thi...

Oct 9, 2025
CVE-2025-4231 7.2

An authenticated command injection vulnerability in Palo Alto Networks PAN-OS allows administrative users with management interface access to execute ...

Jun 13, 2025
CVE-2025-0120 7.0

A privilege escalation vulnerability in Palo Alto Networks GlobalProtect app on Windows allows local non-admin users to gain SYSTEM privileges by expl...

Apr 11, 2025
CVE-2025-0118 8.0

A vulnerability in Palo Alto Networks GlobalProtect app on Windows allows remote attackers to execute ActiveX controls as an authenticated Windows use...

Mar 12, 2025
CVE-2025-0114 7.5

An unauthenticated attacker can cause a Denial of Service (DoS) in Palo Alto Networks PAN-OS GlobalProtect by sending specially crafted packets over t...

Mar 12, 2025
CVE-2025-0108 9.1

An authentication bypass vulnerability in Palo Alto Networks PAN-OS software allows unauthenticated attackers with network access to the management we...

Feb 12, 2025
CVE-2025-0111 6.5

An authenticated file read vulnerability in Palo Alto Networks PAN-OS software allows authenticated attackers with management web interface access to ...

Feb 12, 2025
CVE-2025-0103 8.8

An SQL injection vulnerability in Palo Alto Networks Expedition allows authenticated attackers to extract sensitive database information including pas...

Jan 11, 2025
CVE-2025-0104 6.1

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition allows attackers to execute malicious JavaScript in authenticate...

Jan 11, 2025
CVE-2025-0105 9.1

CVE-2025-0105 is an arbitrary file deletion vulnerability in Palo Alto Networks Expedition that allows unauthenticated attackers to delete files acces...

Jan 11, 2025
CVE-2025-0107 9.8

An unauthenticated OS command injection vulnerability in Palo Alto Networks Expedition allows attackers to execute arbitrary commands as the www-data ...

Jan 11, 2025
CVE-2024-3393 7.5

An unauthenticated attacker can send a malicious DNS packet through a Palo Alto Networks firewall's data plane, causing the firewall to reboot. Repeat...

Dec 27, 2024
CVE-2024-9474 7.2

This CVE describes a privilege escalation vulnerability in Palo Alto Networks PAN-OS software where an authenticated administrator with access to the ...

Nov 18, 2024
CVE-2024-0012 9.8

An authentication bypass vulnerability in Palo Alto Networks PAN-OS software allows unauthenticated attackers with network access to the management we...

Nov 18, 2024
CVE-2024-5920 4.8

This XSS vulnerability in Palo Alto Networks PAN-OS allows an authenticated read-write Panorama administrator to push malicious configurations to PAN-...

Nov 14, 2024
CVE-2024-5918 4.3

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS allows an authorized user with a specially crafted client certificate to...

Nov 14, 2024
CVE-2024-2550 7.5

An unauthenticated attacker can send a specially crafted packet to Palo Alto Networks PAN-OS GlobalProtect gateways, causing a null pointer dereferenc...

Nov 14, 2024
CVE-2024-2552 6.0

This CVE describes a command injection vulnerability in Palo Alto Networks PAN-OS software that allows authenticated administrators to bypass system r...

Nov 14, 2024
CVE-2024-8686 7.2

This CVE describes a command injection vulnerability in Palo Alto Networks PAN-OS software that allows authenticated administrators to bypass system r...

Sep 11, 2024
CVE-2024-8688 4.4

This vulnerability allows authenticated administrators (including read-only admins) with CLI access to read arbitrary files on Palo Alto Networks fire...

Sep 11, 2024
CVE-2024-8690 4.4

A vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows administrators to disable the endpoint detection agent. This could enable mal...

Sep 11, 2024
CVE-2024-8691 7.1

This vulnerability allows an authenticated GlobalProtect user to impersonate another GlobalProtect user, disconnecting the legitimate user while hidin...

Sep 11, 2024
CVE-2024-5914 9.8

CVE-2024-5914 is a critical command injection vulnerability in Palo Alto Networks Cortex XSOAR CommonScripts Pack that allows unauthenticated attacker...

Aug 14, 2024
CVE-2024-5916 4.4

This vulnerability in Palo Alto Networks PAN-OS allows read-only administrators with config log access to unintentionally view secrets, passwords, and...

Aug 14, 2024
CVE-2024-5910 9.8

CVE-2024-5910 is a critical authentication bypass vulnerability in Palo Alto Networks Expedition that allows unauthenticated attackers with network ac...

Jul 10, 2024
CVE-2024-5913 6.1

An improper input validation vulnerability in Palo Alto Networks PAN-OS software allows attackers with physical file system access to elevate privileg...

Jul 10, 2024
CVE-2024-5907 7.0

A local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows authenticated local users to execute programs with...

Jun 12, 2024
CVE-2024-5909 5.5

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows low-privileged local users to disable the endpoint prote...

Jun 12, 2024
CVE-2024-5905 4.4

A local privilege bypass vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows low-privileged users to disrupt some agent functionali...

Jun 12, 2024
CVE-2024-3400 10.0

CVE-2024-3400 is a critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect feature that allows unauthenticated attackers t...

Apr 12, 2024
CVE-2024-3384 7.5

A vulnerability in Palo Alto Networks PAN-OS software allows remote attackers to reboot firewalls by sending Windows NTLM packets from Windows servers...

Apr 10, 2024
CVE-2024-3382 7.5

A memory leak vulnerability in Palo Alto Networks PAN-OS software allows attackers to send crafted packets that eventually cause the firewall to stop ...

Apr 10, 2024
CVE-2023-6790 8.8

This DOM-based XSS vulnerability in Palo Alto Networks PAN-OS allows attackers to execute malicious JavaScript in an administrator's browser by tricki...

Dec 13, 2023
CVE-2023-0009 7.8

This CVE describes a local privilege escalation vulnerability in Palo Alto Networks GlobalProtect app on Windows. It allows a local user to execute pr...

Jun 14, 2023
CVE-2022-0024 7.2

This vulnerability in Palo Alto Networks PAN-OS software allows authenticated administrators to upload malicious configurations that can disrupt syste...

May 11, 2022
CVE-2022-0016 7.4

A local privilege escalation vulnerability in Palo Alto Networks GlobalProtect app's Connect Before Logon feature allows attackers to gain SYSTEM or r...

Feb 10, 2022
CVE-2021-3059 8.1

This CVE-2021-3059 is an OS command injection vulnerability in Palo Alto Networks PAN-OS management interface that allows man-in-the-middle attackers ...

Nov 10, 2021
CVE-2021-3062 8.1

An improper access control vulnerability in PAN-OS allows authenticated GlobalProtect users to access the EC2 instance metadata endpoint on AWS-hosted...

Nov 10, 2021
CVE-2021-3064 9.8

This is a critical memory corruption vulnerability in Palo Alto Networks GlobalProtect portal and gateway interfaces that allows unauthenticated attac...

Nov 10, 2021
CVE-2021-3056 8.8

A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN allows authenticated attackers to execute arbitrary code w...

Nov 10, 2021
CVE-2021-3053 7.5

An unauthenticated attacker can send specially crafted network traffic through Palo Alto Networks PAN-OS firewalls to crash the dataplane service. Rep...

Sep 8, 2021
CVE-2021-3051 8.1

CVE-2021-3051 is an improper cryptographic signature verification vulnerability in Cortex XSOAR's SAML authentication that allows unauthenticated atta...

Sep 8, 2021
CVE-2021-3042 7.8

This CVE describes a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows. An authenticated local user with file...

Jul 15, 2021
CVE-2021-3044 9.8

CVE-2021-3044 is an improper authorization vulnerability in Palo Alto Networks Cortex XSOAR that allows remote unauthenticated attackers with network ...

Jun 22, 2021
CVE-2021-3041 7.8

This CVE describes a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows. It allows authenticated local Windows...

Jun 10, 2021
CVE-2021-3033 9.1

CVE-2021-3033 is an authentication bypass vulnerability in Palo Alto Networks Prisma Cloud Compute console that allows attackers to log in as any auth...

Feb 10, 2021
CVE-2020-2040 9.8

A critical buffer overflow vulnerability in PAN-OS allows unauthenticated attackers to send malicious requests to the Captive Portal or Multi-Factor A...

Sep 9, 2020

Why Monitor Paloaltonetworks Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 49+ known vulnerabilities affecting Paloaltonetworks products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Paloaltonetworks packages in under 60 seconds. No agents required - completely agentless scanning that works across Paloaltonetworks deployments.

Free vulnerability database: Access detailed information about every Paloaltonetworks CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Paloaltonetworks CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Paloaltonetworks CVEs Free