logo

CVE-2024-3400: Critical Vulnerability in GlobalProtect Feature of PAN-OS being Actively Exploited

ID: c2956f9c-9a10-597e-b530-c48d5e103f77

STIX ID: report--c2956f9c-9a10-597e-b530-c48d5e103f77

Feed Name: Arctic Wolf

Threat Score
90/100

Date Published: 2024-04-15

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

On 12 April 2024 Palo Alto Networks disclosed CVE-2024-3400, a critical (CVSS 10.0) GlobalProtect PAN-OS vulnerability affecting versions 10.2, 11.0 and 11.1 that allows unauthenticated remote code execution as root; Volexity reported active exploitation by threat actor UTA0218 that deployed a UPSTYLE Python backdoor, conducted lateral movement, and exfiltrated credentials and files, while Palo Alto prepared hotfixes and recommended interim mitigations (Threat ID 95187 and disabling device telemetry).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.