Skip to content
COOEY

FAIL › dossier

Palo Alto Networks, Inc.

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

Palo Alto Networks is a major cybersecurity vendor whose core PAN-OS platform has suffered a sustained pattern of critical vulnerabilities, including multiple RCEs, authentication bypasses, and command injections that were actively exploited. The company's security posture is compromised by a high volume of severe flaws in its flagship products, requiring urgent patching and architectural review.

PROFILE
CategoryCybersecurityWhat they doPalo Alto Networks develops and sells cybersecurity products, including firewalls, threat intelligence, and cloud security solutions. Websitehttps://www.paloaltonetworks.com ↗
SECURITY POSTURE

The company has a poor security posture, evidenced by a high frequency of critical and high-severity vulnerabilities in its core PAN-OS platform and Expedition product, including multiple remote code execution (RCE) flaws, authentication bypasses, and command injection issues that were actively exploited.

Notable failures
  • CVE-2026-0300: Unauthenticated RCE via out-of-bounds write in User-ID Authentication Portal
  • CVE-2024-9474: OS command injection in PAN-OS management interface enabling privilege escalation
  • CVE-2024-0012: Authentication bypass in web management interface actively exploited
  • CVE-2024-3400: Unauthenticated command injection in GlobalProtect enabling ransomware
  • CVE-2020-2021: SAML authentication bypass allowing attacker to bypass authentication
Patterns: Repeated critical RCE vulnerabilities in PAN-OS across multiple years; Frequent authentication bypass flaws in management interfaces; Command injection and OS command injection in core products; Vulnerabilities in third-party integrations (e.g., Expedition, User-ID)
FAILURE HISTORY · 15
DATEEVENTSEVSUMMARY
2026-05-06 CVE-2026-0300 high Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal.
2024-12-30 CVE-2024-3393 high Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.
2024-11-18 CVE-2024-0012 critical Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks.
2024-11-18 CVE-2024-9474 critical Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation.
2024-11-14 CVE-2024-9465 high Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection.
2024-11-14 CVE-2024-9463 high Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.
2024-11-07 CVE-2024-5910 high Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.
2024-04-12 CVE-2024-3400 critical Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks.
2022-03-25 CVE-2020-2021 critical A flaw in Palo Alto Networks' PAN-OS allowed attackers to bypass authentication, potentially granting unauthorized access to networks and systems.
2025-02-20 CVE-2025-0111 high A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.
2025-02-18 CVE-2025-0108 high A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.
2022-08-22 CVE-2022-0028 high Palo Alto Networks PAN-OS suffered an active RDoS attack due to URL filtering policy misconfiguration.
2022-08-18 CVE-2017-15944 high A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild.
2022-01-10 CVE-2019-1579 critical A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.
2026-05-29 CVE-2026-0257 high Palo Alto Networks PAN-OS allows attackers to bypass authentication and establish unauthorized VPN connections.
FEDRAMP CATALOG PRODUCTS · 2
PRODUCTSTATUSIMPACT
GCS-HIGHReadyHigh
Palo Alto Networks Government Cloud ServicesAuthorizedModerate
Open questions: Exact patching timelines for critical RCE vulnerabilities · Whether DIB/CMMC compliance programs have been impacted by these vulnerabilities
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:18:54.235161+00:00