logo

CVE-2024-3400: Follow Up: Patches Released for Actively Exploited Critical Vulnerability in GlobalProtect Feature of PAN-OS

ID: 3c6bea52-6639-55d2-bc0b-433e2fc64027

STIX ID: report--3c6bea52-6639-55d2-bc0b-433e2fc64027

Feed Name: Arctic Wolf

Threat Score
90/100

Date Published: 2024-04-15

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On April 14, 2024 Palo Alto Networks released hotfixes for CVE-2024-3400 (CVSS 10), a GlobalProtect PAN-OS vulnerability allowing unauthenticated remote code execution as root; Volexity reported active exploitation by threat actor UTA0218 implanting a custom Python backdoor to deploy additional tools and exfiltrate credentials and files. Arctic Wolf strongly recommends upgrading affected PAN-OS versions to the listed fixed releases (11.1.2-h3, 11.0.4-h1, 10.2.9-h1) and applying recommended mitigations such as Threat ID 95187 or disabling device telemetry until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.