Vulnerabilidades en Palo Alto Networks

316 resultados
Análisis Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2019-17435A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for WindEPSS 0.3%CVE-2024-5920MEDIUMPAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate AdministratorEPSS 0.3%CVE-2020-1987LOWGlobal Protect Agent: VPN cookie local information disclosureEPSS 0.3%CVE-2024-9473MEDIUMGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.3%CVE-2025-0124MEDIUMPAN-OS: Authenticated File Deletion Vulnerability on the Management Web InterfaceEPSS 0.3%CVE-2024-9471MEDIUMPAN-OS: Privilege Escalation (PE) Vulnerability in XML APIEPSS 0.3%CVE-2026-0256MEDIUMPAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web InterfaceEPSS 0.3%CVE-2020-1976MEDIUMGlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.EPSS 0.3%CVE-2026-0259MEDIUMWildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)EPSS 0.3%CVE-2026-0241MEDIUMTrust Protection Foundation: Multiple Authorization Bypass VulnerabilitiesEPSS 0.3%CVE-2019-1573LOWInformation Disclosure in GlobalProtect AgentEPSS 0.3%CVE-2020-1991HIGHTraps: Insecure temporary file vulnerability may allow privilege escalation on WindowsEPSS 0.3%CVE-2022-0017HIGHGlobalProtect App: Improper Link Resolution Vulnerability Leads to Local Privilege EscalationEPSS 0.3%CVE-2023-0005MEDIUMPAN-OS: Exposure of Sensitive Information VulnerabilityEPSS 0.3%CVE-2025-0128HIGHPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted PacketEPSS 0.3%CVE-2023-0002MEDIUMCortex XDR Agent: Product Disruption by Local Windows UserEPSS 0.3%CVE-2020-1989HIGHGlobal Protect Agent: Incorrect privilege assignment allows local privilege escalationEPSS 0.3%CVE-2021-3037LOWPAN-OS: Secrets for scheduled configuration exports are logged in system logsEPSS 0.3%CVE-2022-0014MEDIUMCortex XDR Agent: Unintended Program Execution When Using Live Terminal SessionEPSS 0.3%CVE-2024-5916MEDIUMPAN-OS: Cleartext Exposure of External System SecretsEPSS 0.2%