logo

Exploit code for Palo Alto Networks zero-day now public

ID: ee81fc02-78c7-5d74-b785-d81dcc45356e

STIX ID: report--ee81fc02-78c7-5d74-b785-d81dcc45356e

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-04-17

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A maximum-severity vulnerability (CVE-2024-3400) in Palo Alto Networks' PAN-OS GlobalProtect telemetry service allows unauthenticated command injection leading to remote code execution; public proof-of-concept exploits were released shortly after vendor hotfixes and the flaw has been observed in zero-day exploitation. Researchers demonstrated an exploit chain involving file-creation via a crafted SESSID cookie and command injection, and disabling telemetry is no longer a reliable mitigation; Shadowserver reports ~156,000 public GlobalProtect appliances and CISA added the issue to its Known Exploited Vulnerabilities list, prompting urgent patching and available Threat Prevention signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.