← Back

Paloaltonetworks

paloaltonetworks

371 CVEs • 125 products

Products (125)

Click to collapse
Toggle
Pan Os
pan-os
Globalprotect
globalprotect
Expedition
expedition
Cortex Xsoar
cortex_xsoar
Prisma Access
prisma_access
Prisma Cloud
prisma_cloud
Traps
traps
Secdo
secdo
Prisma Sd Wan
prisma_sd-wan
Netconnect
netconnect
Demisto
demisto
Minemeld
minemeld
Twistlock
twistlock
Vm Series
vm-series
Cortex Xsiam
cortex_xsiam
Cloud Ngfw
cloud_ngfw
Broker Vm
broker_vm
Pa 7050
pa-7050
Pa 7080
pa-7080
Pa 200
pa-200
Pa 2020
pa-2020
Pa 2050
pa-2050
Pa 220
pa-220
Pa 3020
pa-3020
Pa 3050
pa-3050
Pa 3060
pa-3060
Pa 3220
pa-3220
Pa 3250
pa-3250
Pa 3260
pa-3260
Pa 500
pa-500
Pa 5200
pa-5200
Pa 800
pa-800
Pa 5410
pa-5410
Pa 5420
pa-5420
Pa 5430
pa-5430
Pa 5440
pa-5440
Pa 5445
pa-5445
Pa 1410
pa-1410
Pa 1420
pa-1420
Pa 3410
pa-3410
Pa 3420
pa-3420
Pa 3430
pa-3430
Pa 3440
pa-3440
Pa 410
pa-410
Pa 410r
pa-410r
Pa 410r 5g
pa-410r-5g
Pa 415
pa-415
Pa 415 5g
pa-415-5g
Pa 440
pa-440
Pa 445
pa-445
Pa 450
pa-450
Pa 450r
pa-450r
Pa 450r 5g
pa-450r-5g
Pa 455
pa-455
Pa 455 5g
pa-455-5g
Pa 455r 5g
pa-455r-5g
Pa 460
pa-460
Pa 501
pa-501
Pa 505
pa-505
Pa 510
pa-510
Pa 520
pa-520
Pa 540
pa-540
Pa 545 Poe
pa-545-poe
Pa 5450
pa-5450
Pa 550
pa-550
Pa 5540
pa-5540
Pa 555 Poe
pa-555-poe
Pa 5550
pa-5550
Pa 5560
pa-5560
Pa 5570
pa-5570
Pa 5580
pa-5580
Pa 560
pa-560
Pa 7500
pa-7500
Pa 7500 Dpc A
pa-7500-dpc-a

CVEs (371)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Expedition
Jun 17, 2026
Jan 11, 2025
9.2 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. Th...Show more
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.Show less
1Paloaltonetworks
2Pan Os
Prisma Access
Jun 17, 2026
Dec 27, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the fi...Show more
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Nov 27, 2024
7.1 HIGH· v4
8.8 HIGH· v3
N/A· v2
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating sys...Show more
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 18, 2024
6.9 MEDIUM· v4
7.2 HIGH· v3
N/A· v2
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW an...Show more
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 18, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative act...Show more
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
4.6 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables imperso...Show more
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This...Show more
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtec...Show more
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
2.1 LOW· v4
4.9 MEDIUM· v3
N/A· v2
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network re...Show more
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
6.8 MEDIUM· v4
6.0 MEDIUM· v3
N/A· v2
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that cau...Show more
A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 14, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially cra...Show more
A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Oct 9, 2024
5.2 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the u...Show more
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Oct 9, 2024
5.1 MEDIUM· v4
4.7 MEDIUM· v3
N/A· v2
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions...Show more
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system administrator (read-only)" access could use an XML API key of a "Virtual system administrator" to perform write operations on the virtual system configuration even though they should be limited to read-only operations.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Oct 9, 2024
5.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to...Show more
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Oct 9, 2024
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition....Show more
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.Show less
1Paloaltonetworks
1Expedition
Jun 17, 2026
Oct 9, 2024
7.0 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phis...Show more
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.Show less
1Paloaltonetworks
1Expedition
Jun 17, 2026
Oct 9, 2024
8.2 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
1Paloaltonetworks
1Expedition
Jun 17, 2026
Oct 9, 2024
9.2 CRITICAL· v4
9.1 CRITICAL· v3
N/A· v2
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. W...Show more
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.Show less
1Paloaltonetworks
1Expedition
Jun 17, 2026
Oct 9, 2024
9.3 CRITICAL· v4
6.5 MEDIUM· v3
N/A· v2
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, devic...Show more
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.Show less