Palo Alto Networks, Inc.
Self-Reporting Analysis
Of all the CVEs published by Palo Alto Networks, Inc. as a CNA, 0.0% affect products that Palo Alto Networks, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Palo Alto Networks, Inc., 0.0% are self-published by Palo Alto Networks, Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Palo Alto Networks, Inc. over time
Top CVEs
All CVEs published by Palo Alto Networks, Inc. as a CNA, regardless of affected vendor or product.
403 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0257CRITICAL Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establi | May 13, 2026 | 9.1 | 99 | YES | YES |
CVE-2024-5910CRITICAL Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
N | Jul 10, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-3400CRITICAL A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinc | Apr 12, 2024 | 10.0 | 99 | YES | YES |
CVE-2024-9474HIGH A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firew | Nov 18, 2024 | 7.2 | 98 | YES | YES |
CVE-2024-0012CRITICAL An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator | Nov 18, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-0108CRITICAL An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authenticat | Feb 12, 2025 | 9.1 | 97 | YES | YES |
CVE-2024-9465CRITICAL An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, devic | Oct 9, 2024 | 9.1 | 97 | YES | YES |
CVE-2024-9463HIGH An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosur | Oct 9, 2024 | 7.5 | 97 | YES | YES |
CVE-2026-0300CRITICAL A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execu | May 6, 2026 | 9.8 | 91 | YES | NO |
CVE-2019-1579HIGH Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled | Jul 19, 2019 | 8.1 | 86 | YES | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (403 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Palo Alto Networks, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Palo Alto Networks, Inc. as a CNA — matched by CVE ID, not by organization name.