Skip to content
COOEY

FAIL › dossier

PAN-OS

PRODUCT

· dossier confidence 20%

Palo Alto Networks is a major public cybersecurity vendor whose PAN-OS platform has demonstrated a severe and recurring security posture, characterized by a high volume of critical RCE, authentication bypass, and buffer overflow vulnerabilities across management interfaces and core network features.

PROFILE
CategoryCybersecurityWhat they doPalo Alto Networks develops and sells cybersecurity solutions, including the PAN-OS operating system for firewalls and network security platforms. Websitehttps://www.paloaltonetworks.com ↗
SECURITY POSTURE

The company's PAN-OS platform has a poor security track record, with a high frequency of critical and high-severity vulnerabilities, particularly remote code execution (RCE) flaws, authentication bypasses, and command injection issues across management interfaces and core features like GlobalProtect and DNS proxy.

Notable failures
  • CVE-2024-0012: Critical RCE via OS command injection in management interface
  • CVE-2024-3400: Critical RCE0day in GlobalProtect enabling ransomware
  • CVE-2026-0264: Critical buffer overflow in DNS proxy and DNS Server features
  • CVE-2026-0258: Critical SSRF in IKEv2 implementation
  • CVE-2026-0263: Critical buffer overflow in IKEv2 processing
  • CVE-2026-0284: Critical unauthenticated XML injection in LSVPN
Patterns: repeated critical RCE vulnerabilities in management interfaces and core features; authentication bypasses in web management interfaces; buffer overflows and SSRF in network protocol implementations (IKEv2, DNS); unpatched 0day vulnerabilities actively exploited in the wild
FAILURE HISTORY · 17
DATEEVENTSEVSUMMARY
2026-05-06 CVE-2026-0300 high Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal.
2024-12-30 CVE-2024-3393 high Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.
2024-11-18 CVE-2024-0012 critical Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks.
2024-11-18 CVE-2024-9474 critical Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation.
2024-04-12 CVE-2024-3400 critical Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks.
2022-03-25 CVE-2020-2021 critical A flaw in Palo Alto Networks' PAN-OS allowed attackers to bypass authentication, potentially granting unauthorized access to networks and systems.
2025-02-20 CVE-2025-0111 high A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.
2025-02-18 CVE-2025-0108 high A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.
2022-08-22 CVE-2022-0028 high Palo Alto Networks PAN-OS suffered an active RDoS attack due to URL filtering policy misconfiguration.
2022-08-18 CVE-2017-15944 high A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild.
2022-01-10 CVE-2019-1579 critical A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.
2026-07-09 CVE-2026-0284 critical Palo Alto Networks PAN-OS suffered a critical unauthenticated XML injection vulnerability in LSVPN that could corrupt satellite data.
2026-05-29 CVE-2026-0257 high Palo Alto Networks PAN-OS allows attackers to bypass authentication and establish unauthorized VPN connections.
2026-05-13 CVE-2026-0264 critical CVE-2026-0264: A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo
2026-05-13 CVE-2026-0258 critical CVE-2026-0258: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o
2026-05-13 CVE-2026-0263 critical CVE-2026-0263: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA
2024-11-18 CVE-2024-0012 critical CVE-2024-0012: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth
Open questions: Exact number of employees and specific organizational structure · Details on internal security processes and vulnerability management workflows
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:22:41.423214+00:00