logo

Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit

ID: 3d61bed4-8010-5f36-9316-21e06dd62cc4

STIX ID: report--3d61bed4-8010-5f36-9316-21e06dd62cc4

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-11-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical unauthenticated remote code execution (RCE) zero-day in Palo Alto Networks PAN-OS management interfaces (CVSS 9.3) is confirmed to be under active exploitation against internet-exposed devices; Palo Alto advises immediately restricting management-interface access to trusted internal IPs while it prepares fixes and threat prevention signatures. The report also notes two other Palo Alto flaws (CVE-2024-9463 and CVE-2024-9465) added to CISA's KEV catalog for which patches have been issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.