Palo Alto Networks PAN-OS vulnerabilities
184 known vulnerabilities affecting palo_alto_networks/pan-os.
Total CVEs
184
CISA KEV
10
actively exploited
Public exploits
10
Exploited in wild
11
Severity breakdown
CRITICAL18HIGH80MEDIUM73LOW13
Vulnerabilities
Page 2 of 10
CVE-2019-17440P2CRITICALCVSS 9.8≥ 9.0, < 9.0.5-h32019-12-20
CVE-2019-17440 [CRITICAL] CWE-923 CVE-2019-17440: Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with s
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to 9.0.5-h3 on PA-7080 and PA-7050 devices with an LFC installed and confi
nvd
CVE-2025-0133P3LOWCVSS 2.7PoC≥ 11.2.0, < 11.2.7≥ 11.1.0, < 11.1.6-h14+2 more2025-05-14
CVE-2025-0133 [LOW] CWE-79 CVE-2025-0133: A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal featur
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credentia
nvd
CVE-2026-0284P2CRITICALCVSS 9.9≥ 12.1.0, < 12.1.4-h8≥ 11.2.0, < 11.2.4-h20+2 more2026-07-09
CVE-2026-0284 [CRITICAL] CWE-74 CVE-2026-0284: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PA
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impa
nvd
CVE-2020-2018P2CRITICALCVSS 9.0v8.0.*≥ 7.1, < 7.1.26+2 more2020-05-13
CVE-2020-2018 [CRITICAL] CWE-287 CVE-2020-2018: An authentication bypass vulnerability in the Panorama context switching feature allows an attacker
An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firewalls. An attacker requires some knowledge of managed firewalls to exploit this issue. This issue does not affect Panorama configured with custom certific
nvd
CVE-2020-2001P2CRITICALCVSS 9.8v8.0.*v7.1.*+2 more2020-05-13
CVE-2020-2001 [CRITICAL] CWE-123 CVE-2020-2001: An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT pr
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate privileges. This issue affects: All PAN-OS 7.1 Panorama and 8.0 Panorama versions; PAN-OS 8
nvd
CVE-2021-3050P2HIGHCVSS 8.8≥ 9.0.10, < 9.0*≥ 9.1.4, < 9.1*+2 more2021-08-11
CVE-2021-3050 [HIGH] CWE-78 CVE-2021-3050: An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an auth
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 version
nvd
CVE-2020-1992P3CRITICALCVSS 9.8≥ 9.0, < 9.0.7≥ 9.1, < 9.1.22020-04-08
CVE-2020-1992 [CRITICAL] CWE-134 CVE-2020-1992: A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log F
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges. This issue affects Palo Alto Networks PAN-OS 9.0 versions before 9.0.7; PAN-OS 9.1 versions befor
nvd
CVE-2020-2014P3HIGHCVSS 8.8v8.0.*v7.1.*+2 more2020-05-13
CVE-2020-2014 [HIGH] CWE-78 CVE-2020-2014: An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inje
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.
nvd
CVE-2021-3056P3HIGHCVSS 8.8≥ 9.0, < 9.0.14≥ 8.1, < 8.1.20+2 more2021-11-10
CVE-2021-3056 [HIGH] CWE-120 CVE-2021-3056: A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than P
nvd
CVE-2020-2015P3HIGHCVSS 8.8v8.0.*≥ 9.0, < 9.0.7+3 more2020-05-13
CVE-2020-2015 [HIGH] CWE-120 CVE-2020-2015: A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash
A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.7; PAN-OS 9.1 versions earlier than 9.1.
nvd
CVE-2026-0258P3CRITICALCVSS 9.1≥ 12.1.0, < 12.1.7, 12.1.4-h5≥ 11.2.0, < 11.2.12, 11.2.10-h6, 11.2.7-h13, 11.2.4-h17+2 more2026-05-13
CVE-2026-0258 [CRITICAL] CWE-918 CVE-2026-0258: A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.
Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabil
nvd
CVE-2026-0286P3HIGHCVSS 7.2≥ 12.1.0, < 12.1.8≥ 11.2.0, < 11.2.13+2 more2026-07-09
CVE-2026-0286 [HIGH] CWE-78 CVE-2026-0286: A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software ena
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
This issue is applicable to PAN-OS softwa
nvd
CVE-2020-2006P3HIGHCVSS 8.8v7.1.*v8.0.*+1 more2020-05-13
CVE-2020-2006 [HIGH] CWE-121 CVE-2020-2006: A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.
nvd
CVE-2020-2039P3MEDIUMCVSS 5.3≥ 9.1, < 9.1.4≥ 8.1, < 8.1.16+2 more2020-09-09
CVE-2020-2039 [MEDIUM] CWE-400 CVE-2020-2039: An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible for an attacker to disrupt the availability of the management web interface by repeatedly uplo
nvd
CVE-2025-0128P3HIGHCVSS 8.7≥ 11.2.0, < 11.2.3≥ 11.1.0, < 11.1.5+3 more2025-04-11
CVE-2025-0128 [HIGH] CWE-754 CVE-2025-0128: A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authent
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.
Cloud NGFW is
nvd
CVE-2026-0288P3HIGHCVSS 7.5≥ 12.1.0, < 12.1.8≥ 11.2.0, < 11.2.13+2 more2026-07-08
CVE-2026-0288 [HIGH] CWE-787 CVE-2026-0288: Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Pal
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
The security risk posed by this issue i
nvd
CVE-2026-0273P3HIGHCVSS 7.2≥ 12.1.0, < 12.1.4-h7≥ 11.2.0, < 11.2.4-h18+2 more2026-06-10
CVE-2026-0273 [HIGH] CWE-78 CVE-2026-0273: A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated ad
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CLI access
nvd
CVE-2026-0310P3HIGHCVSS 7.2≥ 12.2.0, < 12.2.3≥ 12.1.0, < 12.1.4-h10+3 more2026-09-10
CVE-2026-0310 [HIGH] CWE-787 CVE-2026-0310: A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® so
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.
The
nvd
CVE-2020-1998P3HIGHCVSS 8.8v8.0.*≥ 8.1, < 8.1.13+3 more2020-05-13
CVE-2020-1998 [HIGH] CWE-285 CVE-2020-1998: An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linu
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user. This issue affects: PAN-OS 7.1 versio
nvd
CVE-2026-0261P3HIGHCVSS 7.2≥ 12.1.0, < 12.1.7, 12.1.4-h5≥ 11.2.0, < 11.2.12, 11.2.10-h6, 11.2.7-h13, 11.2.4-h17+2 more2026-05-13
CVE-2026-0261 [HIGH] CWE-78 CVE-2026-0261: Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenti
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.
The security risk posed by this issue is significantly minimized when CL
nvd