Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
ID: 3d61bed4-8010-5f36-9316-21e06dd62cc4
STIX ID: report--3d61bed4-8010-5f36-9316-21e06dd62cc4
Feed Name: The Register (Security)
A critical unauthenticated remote code execution (RCE) zero-day in Palo Alto Networks PAN-OS management interfaces (CVSS 9.3) is confirmed to be under active exploitation against internet-exposed devices; Palo Alto advises immediately restricting management-interface access to trusted internal IPs while it prepares fixes and threat prevention signatures. The report also notes two other Palo Alto flaws (CVE-2024-9463 and CVE-2024-9465) added to CISA's KEV catalog for which patches have been issued.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
