paloaltonetworks

310 tracked vulnerabilities.

CVE-2026-0300 CRITICAL KEV
Palo Alto PAN-OS User-ID Authentication Portal - Unauthenticated Root RCE
May 06, 2026
CVSS 9.8
EPSS 0.04
CVE-2026-0227 HIGH
Palo Alto Networks PAN-OS >= 10.1.0 < 10.1.14 - Unauthenticated Denial of Service
Jan 15, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-4615 HIGH
Palo Alto Networks PAN-OS - Privilege Escalation
Oct 09, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-4614 LOW
Palo Alto Networks PAN-OS - Info Disclosure
Oct 09, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-4227 LOW
Palo Alto Networks GlobalProtect <6-0 - Info Disclosure
Jun 13, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-4232 HIGH
Palo Alto Networks GlobalProtect <macOS - Privilege Escalation
Jun 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-4231 HIGH
Palo Alto Networks PAN-OS - Command Injection
Jun 13, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-0135 LOW
Palo Alto Networks GlobalProtect <macOS - Privilege Escalation
May 14, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-0130 HIGH
Palo Alto Networks PAN-OS 11.1.0-11.1.5 and 11.2.0-11.2.4 - Unauthenticated Denial of Service via Malformed Packet Burst
May 14, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-0124 LOW
Palo Alto Networks PAN-OS - Auth Bypass
Apr 11, 2025
CVSS 3.8
EPSS 0.00
CVE-2025-0120 HIGH
Palo Alto Networks GlobalProtect < - Privilege Escalation
Apr 11, 2025
CVSS 7.0
EPSS 0.00
CVE-2025-0118 HIGH
Palo Alto Networks GlobalProtect <Windows - Privilege Escalation
Mar 12, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-0114 HIGH
Palo Alto Networks PAN-OS >= 10.1.0 < 10.1.14 - Unauthenticated Denial of Service via GlobalProtect Packet Flood
Mar 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-0111 MEDIUM KEV
Palo Alto Networks PAN-OS - Info Disclosure
Feb 12, 2025
CVSS 6.5
EPSS 0.04
CVE-2025-0108 CRITICAL KEVNUCLEI
Palo Alto Networks PAN-OS - Auth Bypass
Feb 12, 2025
CVSS 9.1
EPSS 0.94
CVE-2025-0107 CRITICAL NUCLEI
Palo Alto Networks Expedition - Command Injection
Jan 11, 2025
CVSS 9.8
EPSS 0.80
CVE-2025-0106 MEDIUM
Palo Alto Networks Expedition - Info Disclosure
Jan 11, 2025
CVSS 5.3
EPSS 0.01
CVE-2025-0105 CRITICAL
Palo Alto Networks Expedition - Info Disclosure
Jan 11, 2025
CVSS 9.1
EPSS 0.04
CVE-2025-0104 MEDIUM
Palo Alto Networks Expedition - XSS
Jan 11, 2025
CVSS 6.1
EPSS 0.01
CVE-2025-0103 HIGH
Palo Alto Networks Expedition - SQL Injection
Jan 11, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-3393 HIGH KEV
Palo Alto Networks PAN-OS >= 11.1.0 < 11.1.1 - Unauthenticated Denial of Service via Malicious DNS Packet
Dec 27, 2024
CVSS 7.5
EPSS 0.80
CVE-2024-5921 HIGH
Palo Alto Networks GlobalProtect - Improper Certificate Validation
Nov 27, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-9474 HIGH KEVNUCLEI
PAN-OS >=10.1.0 <10.1.14 - Authenticated Privilege Escalation to Root via Management Interface
Nov 18, 2024
CVSS 7.2
EPSS 0.94
CVE-2024-0012 CRITICAL KEVNUCLEI
Palo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass
Nov 18, 2024
CVSS 9.8
EPSS 0.94
CVE-2024-5920 MEDIUM
Palo Alto Networks PAN-OS 10.1.0-10.1.13 - Authenticated Stored Cross-Site Scripting via Configuration Push
Nov 14, 2024
CVSS 4.8
EPSS 0.01