FAIL › dossier
PAN-OS
PRODUCT· dossier confidence 20%
Palo Alto Networks is a major public cybersecurity vendor whose PAN-OS platform has demonstrated a severe and recurring security posture, characterized by a high volume of critical RCE, authentication bypass, and buffer overflow vulnerabilities across management interfaces and core network features.
PROFILE
CategoryCybersecurityWhat they doPalo Alto Networks develops and sells cybersecurity solutions, including the PAN-OS operating system for firewalls and network security platforms.
Websitehttps://www.paloaltonetworks.com ↗
SECURITY POSTURE
The company's PAN-OS platform has a poor security track record, with a high frequency of critical and high-severity vulnerabilities, particularly remote code execution (RCE) flaws, authentication bypasses, and command injection issues across management interfaces and core features like GlobalProtect and DNS proxy.
Notable failures
- CVE-2024-0012: Critical RCE via OS command injection in management interface
- CVE-2024-3400: Critical RCE0day in GlobalProtect enabling ransomware
- CVE-2026-0264: Critical buffer overflow in DNS proxy and DNS Server features
- CVE-2026-0258: Critical SSRF in IKEv2 implementation
- CVE-2026-0263: Critical buffer overflow in IKEv2 processing
- CVE-2026-0284: Critical unauthenticated XML injection in LSVPN
Patterns: repeated critical RCE vulnerabilities in management interfaces and core features; authentication bypasses in web management interfaces; buffer overflows and SSRF in network protocol implementations (IKEv2, DNS); unpatched 0day vulnerabilities actively exploited in the wild
FAILURE HISTORY · 17
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-06 | CVE-2026-0300 | high | Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal. |
| 2024-12-30 | CVE-2024-3393 | high | Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws. |
| 2024-11-18 | CVE-2024-0012 | critical | Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks. |
| 2024-11-18 | CVE-2024-9474 | critical | Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation. |
| 2024-04-12 | CVE-2024-3400 | critical | Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks. |
| 2022-03-25 | CVE-2020-2021 | critical | A flaw in Palo Alto Networks' PAN-OS allowed attackers to bypass authentication, potentially granting unauthorized access to networks and systems. |
| 2025-02-20 | CVE-2025-0111 | high | A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations. |
| 2025-02-18 | CVE-2025-0108 | high | A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely. |
| 2022-08-22 | CVE-2022-0028 | high | Palo Alto Networks PAN-OS suffered an active RDoS attack due to URL filtering policy misconfiguration. |
| 2022-08-18 | CVE-2017-15944 | high | A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild. |
| 2022-01-10 | CVE-2019-1579 | critical | A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces. |
| 2026-07-09 | CVE-2026-0284 | critical | Palo Alto Networks PAN-OS suffered a critical unauthenticated XML injection vulnerability in LSVPN that could corrupt satellite data. |
| 2026-05-29 | CVE-2026-0257 | high | Palo Alto Networks PAN-OS allows attackers to bypass authentication and establish unauthorized VPN connections. |
| 2026-05-13 | CVE-2026-0264 | critical | CVE-2026-0264: A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo |
| 2026-05-13 | CVE-2026-0258 | critical | CVE-2026-0258: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o |
| 2026-05-13 | CVE-2026-0263 | critical | CVE-2026-0263: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA |
| 2024-11-18 | CVE-2024-0012 | critical | CVE-2024-0012: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth |
DOSSIER SOURCES
- Nir Zuk - Forbes · www.forbes.com
- ASML Holding (ASML) Company Profile & Description - Stock Analysis · stockanalysis.com
- Palo Alto Networks Inc, PANW:NSQ profile - FT.com · markets.ft.com
- Palo Alto Networks (PANW) Company Profile, History, Products & Services · www.financecharts.com
- Palo Alto Networks (PANW) Statistics & Valuation · stockanalysis.com
- Palo Alto Networks Inc, PANW:NSQ profile - FT.com · markets.ft.com
Open questions: Exact number of employees and specific organizational structure · Details on internal security processes and vulnerability management workflows
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:22:41.423214+00:00