Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2025-0137MEDIUMPAN-OS: Improper Neutralization of Input in the Management Web InterfaceEPSS 0.4%CVE-2025-0126HIGHPAN-OS: Session Fixation Vulnerability in GlobalProtect SAML LoginEPSS 0.4%CVE-2024-0007MEDIUMPAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web InterfaceEPSS 0.4%CVE-2026-0250MEDIUMGlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or GatewayEPSS 0.4%CVE-2024-2432MEDIUMGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.4%CVE-2024-0011MEDIUMPAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal AuthenticationEPSS 0.4%CVE-2024-9470MEDIUMCortex XSOAR: Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-0283MEDIUMPAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)EPSS 0.4%CVE-2023-0010MEDIUMPAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal AuthenticationEPSS 0.4%CVE-2026-0263HIGHPAN-OS: Remote Code Execution (RCE) in IKEv2 ProcessingEPSS 0.4%CVE-2020-1988MEDIUMGlobal Protect Agent: Local privilege escalation due to an unquoted search path vulnerabilityEPSS 0.4%CVE-2024-5908MEDIUMGlobalProtect App: Encrypted Credential Exposure via Log FilesEPSS 0.4%CVE-2020-1981HIGHPAN-OS: Predictable temporary filename vulnerability allows local privilege escalationEPSS 0.4%CVE-2026-0262MEDIUMPAN-OS: Denial of Service Vulnerabilities in Network Traffic ParsingEPSS 0.4%CVE-2025-0104HIGHExpedition: Cross-Site Scripting (XSS) VulnerabilityEPSS 0.4%CVE-2025-0138LOWPrisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web InterfaceEPSS 0.4%CVE-2024-3388MEDIUMPAN-OS: User Impersonation in GlobalProtect SSL VPNEPSS 0.3%CVE-2020-2049HIGHCortex XDR Agent: Improper control of loaded DLL leads to local privilege escalationEPSS 0.3%CVE-2025-0124MEDIUMPAN-OS: Authenticated File Deletion Vulnerability on the Management Web InterfaceEPSS 0.3%CVE-2020-2048LOWPAN-OS: System proxy passwords may be logged in clear text while viewing system stateEPSS 0.3%