Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2024-5919MEDIUMPAN-OS: Authenticated XML External Entities (XXE) Injection VulnerabilityEPSS 0.3%CVE-2024-5920MEDIUMPAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate AdministratorEPSS 0.3%CVE-2026-0310HIGHPAN-OS: Buffer Overflow Vulnerability via XML ProcessingEPSS 0.3%CVE-2026-0280LOWPAN-OS: IPv6 Firewall Policy BypassEPSS 0.3%CVE-2026-0259MEDIUMWildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)EPSS 0.3%CVE-2026-0241MEDIUMTrust Protection Foundation: Multiple Authorization Bypass VulnerabilitiesEPSS 0.3%CVE-2019-17437HIGHPAN-OS: Custom-role users may escalate privilegesEPSS 0.3%CVE-2026-0298MEDIUMGlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)EPSS 0.3%CVE-2026-0258MEDIUMPAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL FetchingEPSS 0.3%CVE-2023-3280MEDIUMCortex XDR Agent: Local Windows User Can Disable the AgentEPSS 0.3%CVE-2024-8691MEDIUMPAN-OS: User Impersonation in GlobalProtect PortalEPSS 0.3%CVE-2026-0301LOWPAN-OS: Information Disclosure Vulnerability in URL FilteringEPSS 0.3%CVE-2025-0128HIGHPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted PacketEPSS 0.3%CVE-2020-2004MEDIUMGlobalProtect App: Passwords may be logged in clear text while collecting troubleshooting logsEPSS 0.3%CVE-2026-0297MEDIUMGlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel HandshakeEPSS 0.3%CVE-2019-17436A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12EPSS 0.3%CVE-2020-2020MEDIUMCortex XDR Agent: Exceptional condition denial-of-service (DoS)EPSS 0.3%CVE-2020-1978MEDIUMVM-Series on Microsoft Azure: Inadvertent collection of credentials in Tech support files on HA configured VMsEPSS 0.3%CVE-2020-1987LOWGlobal Protect Agent: VPN cookie local information disclosureEPSS 0.3%CVE-2023-0002MEDIUMCortex XDR Agent: Product Disruption by Local Windows UserEPSS 0.3%