Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2024-5917LOWPAN-OS: Server-Side Request Forgery in WildFireEPSS 0.5%CVE-2026-0284MEDIUMPAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)EPSS 0.5%CVE-2023-38046MEDIUMPAN-OS: Read System Files and Resources During Configuration CommitEPSS 0.5%CVE-2021-3047MEDIUMPAN-OS: Weak Cryptography Used in Web Interface AuthenticationEPSS 0.5%CVE-2020-1982MEDIUMPAN-OS: TLS 1.0 usage for certain communications with Palo Alto Networks cloud delivered servicesEPSS 0.4%CVE-2025-0118MEDIUMGlobalProtect App: Execution of Unsafe ActiveX Control VulnerabilityEPSS 0.4%CVE-2026-0309MEDIUMPAN-OS: Authenticated Command Injection in CLI with Luna HSM ConfigurationEPSS 0.4%CVE-2025-4232HIGHGlobalProtect: Authenticated Code Injection Through Wildcard on macOSEPSS 0.4%CVE-2025-0132MEDIUMCortex XDR Broker VM: Unauthenticated User Can Disable Internal ServicesEPSS 0.4%CVE-2024-3386MEDIUMPAN-OS: Predefined Decryption Exclusions Does Not Work as IntendedEPSS 0.4%CVE-2020-1993LOWPAN-OS: GlobalProtect Portal PHP session fixation vulnerabilityEPSS 0.4%CVE-2024-9472HIGHPAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted TrafficEPSS 0.4%CVE-2023-0007MEDIUMPAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web InterfaceEPSS 0.4%CVE-2025-0130HIGHPAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted PacketsEPSS 0.4%CVE-2025-0125MEDIUMPAN-OS: Improper Neutralization of Input in the Management Web InterfaceEPSS 0.4%CVE-2023-6789MEDIUMPAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web InterfaceEPSS 0.4%CVE-2024-5909MEDIUMCortex XDR Agent: Local Windows User Can Disable the AgentEPSS 0.4%CVE-2024-9468HIGHPAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted PacketEPSS 0.4%CVE-2024-8687MEDIUMPAN-OS: Cleartext Exposure of GlobalProtect Portal PasscodesEPSS 0.4%CVE-2025-0114HIGHPAN-OS: Denial of Service (DoS) in GlobalProtectEPSS 0.4%