FAIL › dossier
Palo Alto Networks, Inc.
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 20%
Palo Alto Networks is a major cybersecurity vendor whose core PAN-OS platform has suffered a sustained pattern of critical vulnerabilities, including multiple RCEs, authentication bypasses, and command injections that were actively exploited. The company's security posture is compromised by a high volume of severe flaws in its flagship products, requiring urgent patching and architectural review.
The company has a poor security posture, evidenced by a high frequency of critical and high-severity vulnerabilities in its core PAN-OS platform and Expedition product, including multiple remote code execution (RCE) flaws, authentication bypasses, and command injection issues that were actively exploited.
- CVE-2026-0300: Unauthenticated RCE via out-of-bounds write in User-ID Authentication Portal
- CVE-2024-9474: OS command injection in PAN-OS management interface enabling privilege escalation
- CVE-2024-0012: Authentication bypass in web management interface actively exploited
- CVE-2024-3400: Unauthenticated command injection in GlobalProtect enabling ransomware
- CVE-2020-2021: SAML authentication bypass allowing attacker to bypass authentication
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-06 | CVE-2026-0300 | high | Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal. |
| 2024-12-30 | CVE-2024-3393 | high | Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws. |
| 2024-11-18 | CVE-2024-0012 | critical | Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks. |
| 2024-11-18 | CVE-2024-9474 | critical | Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation. |
| 2024-11-14 | CVE-2024-9465 | high | Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection. |
| 2024-11-14 | CVE-2024-9463 | high | Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys. |
| 2024-11-07 | CVE-2024-5910 | high | Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access. |
| 2024-04-12 | CVE-2024-3400 | critical | Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks. |
| 2022-03-25 | CVE-2020-2021 | critical | A flaw in Palo Alto Networks' PAN-OS allowed attackers to bypass authentication, potentially granting unauthorized access to networks and systems. |
| 2025-02-20 | CVE-2025-0111 | high | A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations. |
| 2025-02-18 | CVE-2025-0108 | high | A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely. |
| 2022-08-22 | CVE-2022-0028 | high | Palo Alto Networks PAN-OS suffered an active RDoS attack due to URL filtering policy misconfiguration. |
| 2022-08-18 | CVE-2017-15944 | high | A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild. |
| 2022-01-10 | CVE-2019-1579 | critical | A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces. |
| 2026-05-29 | CVE-2026-0257 | high | Palo Alto Networks PAN-OS allows attackers to bypass authentication and establish unauthorized VPN connections. |
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| GCS-HIGH | Ready | High |
| Palo Alto Networks Government Cloud Services | Authorized | Moderate |
- Palo Alto Networks Releases Urgent Security Patches Addressing Thirteen ... · squirrelvpn.com
- Palo Alto Networks CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- CVE-2026-0261 | Tenable® · www.tenable.com