Palo Alto Networks known exploited vulnerabilities
CISA lists 15 Palo Alto Networks CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-05-29), and 6 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-3400 (PAN-OS): EPSS 100.0%, added 2024-04-12
- CVE-2024-0012 (PAN-OS): EPSS 99.8%, added 2024-11-18
- CVE-2024-9465 (Expedition): EPSS 99.6%, added 2024-11-14
- CVE-2024-9463 (Expedition): EPSS 98.5%, added 2024-11-14
- CVE-2025-0108 (PAN-OS): EPSS 98.5%, added 2025-02-18
Most affected Palo Alto Networks products
PAN-OS (12), Expedition (3).
All Palo Alto Networks CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-0257 | PAN-OS | PAN-OS Authentication Bypass | 2026-05-29 | 2026-06-01 | 96.4% | Yes |
| CVE-2026-0300 | PAN-OS | PAN-OS Out-of-bounds Write | 2026-05-06 | 2026-05-09 | 31.7% | – |
| CVE-2025-0111 | PAN-OS | PAN-OS File Read | 2025-02-20 | 2025-03-13 | 2.0% | – |
| CVE-2025-0108 | PAN-OS | PAN-OS Authentication Bypass | 2025-02-18 | 2025-03-11 | 98.5% | – |
| CVE-2024-3393 | PAN-OS | PAN-OS Malicious DNS Packet | 2024-12-30 | 2025-01-20 | 28.4% | – |
| CVE-2024-9474 | PAN-OS | PAN-OS Management Interface OS Command Injection | 2024-11-18 | 2024-12-09 | 94.7% | Yes |
| CVE-2024-0012 | PAN-OS | PAN-OS Management Interface Authentication Bypass | 2024-11-18 | 2024-12-09 | 99.8% | Yes |
| CVE-2024-9465 | Expedition | Expedition SQL Injection | 2024-11-14 | 2024-12-05 | 99.6% | – |
| CVE-2024-9463 | Expedition | Expedition OS Command Injection | 2024-11-14 | 2024-12-05 | 98.5% | – |
| CVE-2024-5910 | Expedition | Expedition Missing Authentication | 2024-11-07 | 2024-11-28 | 91.8% | – |
| CVE-2024-3400 | PAN-OS | PAN-OS Command Injection | 2024-04-12 | 2024-04-19 | 100.0% | Yes |
| CVE-2022-0028 | PAN-OS | PAN-OS Reflected Amplification Denial-of-Service | 2022-08-22 | 2022-09-12 | 2.4% | – |
| CVE-2017-15944 | PAN-OS | PAN-OS Remote Code Execution | 2022-08-18 | 2022-09-08 | 98.3% | – |
| CVE-2020-2021 | PAN-OS | PAN-OS Authentication Bypass | 2022-03-25 | 2022-04-15 | 4.4% | Yes |
| CVE-2019-1579 | PAN-OS | PAN-OS Remote Code Execution | 2022-01-10 | 2022-07-10 | 46.2% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors