Palo Alto Networks, Inc.

First CVE: Aug 16, 2018Active for: 8 years
403
CVEs Published
More CVEs Published than 85% of tracked CNAs
44.8
Avg CVEs / Year
More Avg CVEs / Year than 83% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked CNAs
3.5%
In CISA KEV
Higher KEV Rate than 95% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Palo Alto Networks, Inc. as a CNA, 0.0% affect products that Palo Alto Networks, Inc. develops as a vendor.

100.0%
Self-reported: 0Third-party: 403

Of all the CVEs published that affect products developed by Palo Alto Networks, Inc., 0.0% are self-published by Palo Alto Networks, Inc. as a CNA.

100.0%
Self-published: 0Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by Palo Alto Networks, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2018
7 years ago
Most Recent CVE
Jul 9, 2026
19 days ago

Top CVEs

All CVEs published by Palo Alto Networks, Inc. as a CNA, regardless of affected vendor or product.

403 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establi
May 13, 20269.199YESYES
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. N
Jul 10, 20249.899YESYES
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinc
Apr 12, 202410.099YESYES
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firew
Nov 18, 20247.298YESYES
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator
Nov 18, 20249.898YESYES
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authenticat
Feb 12, 20259.197YESYES
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, devic
Oct 9, 20249.197YESYES
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosur
Oct 9, 20247.597YESYES
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execu
May 6, 20269.891YESNO
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled
Jul 19, 20198.186YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA403 CVEs
Severity distribution among all CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local123 (30.5%)
Network260 (64.5%)
Unknown0 (0.0%)
Physical7 (1.7%)
Adjacent Network11 (2.7%)
Attack Complexity
Low367 (91.1%)
High36 (8.9%)
Unknown0 (0.0%)
User Interaction
None347 (86.1%)
Unknown0 (0.0%)
Required44 (10.9%)
Privileges Required
Low162 (40.2%)
High91 (22.6%)
None150 (37.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (403 CVEs).

CISA KEV
14 CVEs
3.5% of CVEs· 95th percentile
Metasploit
5 CVEs
1.2% of CVEs· 88th percentile
Nuclei
13 CVEs
3.2% of CVEs· 90th percentile
ExploitDB
4 CVEs
1.0% of CVEs· 82nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Palo Alto Networks, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Palo Alto Networks, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs