Paloaltonetworks PAN-OS vulnerabilities
234 known vulnerabilities affecting paloaltonetworks/pan-os.
Total CVEs
234
CISA KEV
14
actively exploited
Public exploits
18
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH90MEDIUM95LOW9
Vulnerabilities
Page 5 of 12
CVE-2025-4231P3HIGHCVSS 7.2≥ 10.2.0, < 10.2.8≥ 11.0.0, < 11.0.32025-06-13
CVE-2025-4231 [HIGH] CWE-77 CVE-2025-4231: A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrat
A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user.
The attacker must have network access to the management web interface and successfully authenticate to exploit this issue.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
nvd
CVE-2026-0283P3HIGHCVSS 7.2≥ 10.2.0, < 10.2.7≥ 10.2.8, < 10.2.10+201 more2026-07-09
CVE-2026-0283 [HIGH] CWE-306 CVE-2026-0283: An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networ
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
nvd
CVE-2026-0272P3HIGHCVSS 7.2≥ 10.2.0, < 10.2.7≥ 10.2.8, < 10.2.10+183 more2026-06-10
CVE-2026-0272 [HIGH] CWE-862 CVE-2026-0272: A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and b
nvd
CVE-2019-1575P3HIGHCVSS 8.8fixed in 7.1.24≥ 8.0.0, < 8.0.19+3 more2019-07-16
CVE-2019-1575 [HIGH] CWE-200 CVE-2019-1575: Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
nvd
CVE-2020-2000P3HIGHCVSS 7.2≥ 8.1.0, < 8.1.16≥ 9.0.0, < 9.0.10+2 more2020-11-12
CVE-2020-2000 [HIGH] CWE-20 CVE-2020-2000: An OS command injection and memory corruption vulnerability in the PAN-OS management web interface t
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0
nvd
CVE-2019-1572P3HIGHCVSS 7.5v9.0.02019-03-26
CVE-2019-1572 [HIGH] CVE-2019-1572: PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.
PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.
nvd
CVE-2016-3654P3HIGHCVSS 7.2≥ 5.0.0, < 5.0.18≥ 5.1, < 5.1.11+3 more2016-04-12
CVE-2016-3654 [HIGH] CWE-20 CVE-2016-3654: The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.
nvd
CVE-2020-2030P3HIGHCVSS 7.2≥ 7.1.0, ≤ 7.1.26≥ 8.0.0, ≤ 8.0.20+1 more2020-07-08
CVE-2020-2030 [HIGH] CWE-78 CVE-2020-2030: An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated a
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-OS 7.1 and PAN-OS 8.0. This issue does not impact PAN-OS 9.0, PAN-OS 9.1, or Prisma Access servi
nvd
CVE-2020-2028P3HIGHCVSS 7.2≥ 7.1.0, ≤ 7.1.26≥ 8.0.0, ≤ 8.0.20+2 more2020-06-10
CVE-2020-2028 [HIGH] CWE-78 CVE-2020-2028: An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrator
An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS
nvd
CVE-2020-2029P3HIGHCVSS 7.2≥ 7.1.0, < 7.1.26≥ 8.0.0, ≤ 8.0.20+1 more2020-06-10
CVE-2020-2029 [HIGH] CWE-78 CVE-2020-2029: An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated ad
An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration. This issue affects: All versions of PAN-OS 8.0; PAN-OS 7.1 versions earlier than PAN-OS 7.1.
nvd
CVE-2026-0280P3HIGHCVSS 7.2≥ 10.2.0, < 10.2.7≥ 10.2.8, < 10.2.10+201 more2026-07-09
CVE-2026-0280 [HIGH] CWE-131 CVE-2026-0280: An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enab
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability.
nvd
CVE-2024-0008P3HIGHCVSS 8.8≥ 10.2.0, < 10.2.5≥ 11.0.0, < 11.0.2+7 more2024-02-14
CVE-2024-0008 [HIGH] CWE-613 CVE-2024-0008: Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in cert
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
nvd
CVE-2020-2002P3HIGHCVSS 8.1≥ 7.1.0, < 7.1.26≥ 8.0.0, ≤ 8.0.20+2 more2020-05-13
CVE-2020-2002 [HIGH] CWE-290 CVE-2020-2002: An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID c
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle t
nvd
CVE-2017-9458P3CRITICALCVSS 9.8≤ 6.1.17v7.0.0+27 more2017-09-07
CVE-2017-9458 [CRITICAL] CWE-611 CVE-2017-9458: XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via
nvd
CVE-2020-2007P3HIGHCVSS 7.2≥ 7.1.0, ≤ 7.1.26≥ 8.0.0, ≤ 8.0.20+2 more2020-05-13
CVE-2020-2007 [HIGH] CWE-78 CVE-2020-2007: An OS command injection vulnerability in the management server component of PAN-OS allows an authent
An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.
nvd
CVE-2020-2009P3HIGHCVSS 7.2≥ 7.1.0, ≤ 7.1.26≥ 8.0.0, ≤ 8.0.20+2 more2020-05-13
CVE-2020-2009 [HIGH] CWE-73 CVE-2020-2009: An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS P
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions. This issue a
nvd
CVE-2021-3058P3HIGHCVSS 7.2≥ 8.1.0, ≤ 8.1.20≥ 9.0.0, ≤ 9.0.14+3 more2021-11-10
CVE-2021-3058 [HIGH] CWE-78 CVE-2021-3058: An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an auth
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.
nvd
CVE-2022-0024P3HIGHCVSS 7.2≥ 8.1.0, < 8.1.23≥ 9.0.0, < 9.0.16+3 more2022-05-11
CVE-2022-0024 [HIGH] CWE-138 CVE-2022-0024: A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-b
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the configuration is committed on both hardware and virtual firewalls. This issue does
nvd
CVE-2026-0262P3HIGHCVSS 7.5fixed in 10.2.7≥ 10.2.8, < 10.2.10+169 more2026-05-13
CVE-2026-0262 [HIGH] CWE-754 CVE-2026-0262: Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthent
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic.
Panorama and Cloud NGFW are not impacted by these vulnerabilities.
nvd
CVE-2021-3061P3HIGHCVSS 7.2≥ 8.1.0, ≤ 8.1.20≥ 9.0.0, ≤ 9.0.14+3 more2021-11-10
CVE-2021-3061 [HIGH] CWE-78 CVE-2021-3061: An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI)
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versi
nvd