Brand
Palo Alto Networks: actively exploited vulnerabilities
15 vulnerabilities in Palo Alto Networks products (PAN-OS / GlobalProtect, Expedition) are in CISA’s catalog of exploited vulnerabilities. Last added: May 29, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
15 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Palo Alto Networks category to your radar, or open its page.
- Firewalls, VPNs and remote access 15 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- PAN-OS / GlobalProtect 12 vulnerabilities · Firewalls and VPNs
- Expedition 3 vulnerabilities · Firewalls and VPNs
Name used by CISA: Palo Alto Networks. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Palo Alto Networks list.
Rank 1Palo Alto Networks PAN-OS / GlobalProtect
CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 6, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Palo Alto Networks PAN-OS / GlobalProtect
CVE-2026-0257Ransomware
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 29, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.1 (critical)
Rank 3Palo Alto Networks PAN-OS / GlobalProtect
CVE-2024-3400Ransomware
Palo Alto Networks PAN-OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 12, 2024
- CISA deadline
- 7 days
- CVSS severity
- 10.0 (critical)
Rank 4Palo Alto Networks PAN-OS / GlobalProtect
CVE-2020-2021RansomwareCVE from 2020, added in 2022
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 5Palo Alto Networks PAN-OS / GlobalProtect
CVE-2024-0012Ransomware
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6Palo Alto Networks Expedition
CVE-2024-5910Palo Alto Networks Expedition Missing Authentication Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 7, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7Palo Alto Networks PAN-OS / GlobalProtect
CVE-2017-15944CVE from 2017, added in 2022
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 18, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Palo Alto Networks PAN-OS / GlobalProtect
CVE-2025-0108Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 18, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 9Palo Alto Networks Expedition
CVE-2024-9465Palo Alto Networks Expedition SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 14, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 10Palo Alto Networks PAN-OS / GlobalProtect
CVE-2022-0028Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 22, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.6 (high)
Show 5 more vulnerabilities
Rank 11Palo Alto Networks PAN-OS / GlobalProtect
CVE-2019-1579RansomwareCVE from 2019, added in 2022
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 8.1 (high)
Rank 12Palo Alto Networks PAN-OS / GlobalProtect
CVE-2024-3393Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 30, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 13Palo Alto Networks Expedition
CVE-2024-9463Palo Alto Networks Expedition OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 14, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 14Palo Alto Networks PAN-OS / GlobalProtect
CVE-2024-9474Ransomware
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 15Palo Alto Networks PAN-OS / GlobalProtect
CVE-2025-0111Palo Alto Networks PAN-OS File Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 20, 2025
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Follow and verify
Get new Palo Alto Networks vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.