Vendor Exploitation Record

Palo Alto Networks — Known Exploited Vulnerabilities

15 in CISA KEV · 6 ransomware-linked · as of 2026-08-31
In CISA KEV15 confirmed exploited
Ransomware-linked6 (40% of KEV, per CISA)
First KEV addition2022-01-10
Most recent2026-05-29

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Palo Alto Networks (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Palo Alto Networks vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2026-0257PAN-OSPalo Alto Networks PAN-OS Authentication Bypass Vulnerability2026-05-29ransomware
CVE-2026-0300PAN-OSPalo Alto Networks PAN-OS Out-of-bounds Write Vulnerability2026-05-06
CVE-2025-0111PAN-OSPalo Alto Networks PAN-OS File Read Vulnerability2025-02-20
CVE-2025-0108PAN-OSPalo Alto Networks PAN-OS Authentication Bypass Vulnerability2025-02-18
CVE-2024-3393PAN-OSPalo Alto Networks PAN-OS Malicious DNS Packet Vulnerability2024-12-30
CVE-2024-9474PAN-OSPalo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability2024-11-18ransomware
CVE-2024-0012PAN-OSPalo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability2024-11-18ransomware
CVE-2024-9465ExpeditionPalo Alto Networks Expedition SQL Injection Vulnerability2024-11-14
CVE-2024-9463ExpeditionPalo Alto Networks Expedition OS Command Injection Vulnerability2024-11-14
CVE-2024-5910ExpeditionPalo Alto Networks Expedition Missing Authentication Vulnerability2024-11-07
CVE-2024-3400PAN-OSPalo Alto Networks PAN-OS Command Injection Vulnerability2024-04-12ransomware
CVE-2022-0028PAN-OSPalo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability2022-08-22
CVE-2017-15944PAN-OSPalo Alto Networks PAN-OS Remote Code Execution Vulnerability2022-08-18
CVE-2020-2021PAN-OSPalo Alto Networks PAN-OS Authentication Bypass Vulnerability2022-03-25ransomware
CVE-2019-1579PAN-OSPalo Alto Networks PAN-OS Remote Code Execution Vulnerability2022-01-10ransomware

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.