Palo Alto Networks PAN-OS known exploited vulnerabilities, ranked
CISA lists 12 Palo Alto Networks PAN-OS CVEs as exploited in the wild. 2 were added in the last 12 months and 6 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2024-3400: EPSS 100.00%, used in ransomware, added 2024-04-12
- CVE-2024-0012: EPSS 99.86%, used in ransomware, added 2024-11-18
- CVE-2025-0108: EPSS 98.5%, added 2025-02-18
- CVE-2017-15944: EPSS 98.3%, added 2022-08-18
- CVE-2026-0257: EPSS 96.4%, used in ransomware, added 2026-05-29
All 12 Palo Alto Networks PAN-OS CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2024-3400 | PAN-OS Command Injection | 100.00% | Yes | 2024-04-12 | 2024-04-19 |
| 2 | CVE-2024-0012 | PAN-OS Management Interface Authentication Bypass | 99.86% | Yes | 2024-11-18 | 2024-12-09 |
| 3 | CVE-2025-0108 | PAN-OS Authentication Bypass | 98.5% | – | 2025-02-18 | 2025-03-11 |
| 4 | CVE-2017-15944 | PAN-OS Remote Code Execution | 98.3% | – | 2022-08-18 | 2022-09-08 |
| 5 | CVE-2026-0257 | PAN-OS Authentication Bypass | 96.4% | Yes | 2026-05-29 | 2026-06-01 |
| 6 | CVE-2024-9474 | PAN-OS Management Interface OS Command Injection | 94.8% | Yes | 2024-11-18 | 2024-12-09 |
| 7 | CVE-2019-1579 | PAN-OS Remote Code Execution | 46.2% | Yes | 2022-01-10 | 2022-07-10 |
| 8 | CVE-2026-0300 | PAN-OS Out-of-bounds Write | 31.7% | – | 2026-05-06 | 2026-05-09 |
| 9 | CVE-2024-3393 | PAN-OS Malicious DNS Packet | 28.6% | – | 2024-12-30 | 2025-01-20 |
| 10 | CVE-2020-2021 | PAN-OS Authentication Bypass | 4.4% | Yes | 2022-03-25 | 2022-04-15 |
| 11 | CVE-2022-0028 | PAN-OS Reflected Amplification Denial-of-Service | 2.4% | – | 2022-08-22 | 2022-09-12 |
| 12 | CVE-2025-0111 | PAN-OS File Read | 2.0% | – | 2025-02-20 | 2025-03-13 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Palo Alto Networks KEV CVEs · free KEV badge for Palo Alto Networks · all vendors