CyberMax
Home › Exploited CVEs

Palo Alto Networks known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 15 Palo Alto Networks CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-05-29), and 6 are known to be used in ransomware campaigns.

Palo Alto Networks CVEs added to CISA KEV per year
2022: 4202242024: 7202472025: 2202522026: 220262

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Palo Alto Networks products

PAN-OS (12), Expedition (3).

All Palo Alto Networks CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-0257PAN-OSPAN-OS Authentication Bypass2026-05-292026-06-0196.4%Yes
CVE-2026-0300PAN-OSPAN-OS Out-of-bounds Write2026-05-062026-05-0931.7%–
CVE-2025-0111PAN-OSPAN-OS File Read2025-02-202025-03-132.0%–
CVE-2025-0108PAN-OSPAN-OS Authentication Bypass2025-02-182025-03-1198.5%–
CVE-2024-3393PAN-OSPAN-OS Malicious DNS Packet2024-12-302025-01-2028.4%–
CVE-2024-9474PAN-OSPAN-OS Management Interface OS Command Injection2024-11-182024-12-0994.7%Yes
CVE-2024-0012PAN-OSPAN-OS Management Interface Authentication Bypass2024-11-182024-12-0999.8%Yes
CVE-2024-9465ExpeditionExpedition SQL Injection2024-11-142024-12-0599.6%–
CVE-2024-9463ExpeditionExpedition OS Command Injection2024-11-142024-12-0598.5%–
CVE-2024-5910ExpeditionExpedition Missing Authentication2024-11-072024-11-2891.8%–
CVE-2024-3400PAN-OSPAN-OS Command Injection2024-04-122024-04-19100.0%Yes
CVE-2022-0028PAN-OSPAN-OS Reflected Amplification Denial-of-Service2022-08-222022-09-122.4%–
CVE-2017-15944PAN-OSPAN-OS Remote Code Execution2022-08-182022-09-0898.3%–
CVE-2020-2021PAN-OSPAN-OS Authentication Bypass2022-03-252022-04-154.4%Yes
CVE-2019-1579PAN-OSPAN-OS Remote Code Execution2022-01-102022-07-1046.2%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors