logo

Follow-Up: Arctic Wolf Observes Ongoing Exploitation of Critical Palo Alto Networks Vulnerability CVE-2024-0012 Chained with CVE-2024-9474

ID: 8ba81afa-191d-5579-88f5-47144bab3cef

STIX ID: report--8ba81afa-191d-5579-88f5-47144bab3cef

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2024-11-20

Date Updated: 2026-04-27

...
...

Arctic Wolf reports active exploitation of PAN-OS vulnerabilities CVE-2024-0012 and CVE-2024-9474 that can be chained to allow unauthenticated threat actors to gain administrator/root access to affected Palo Alto firewalls; a public PoC was released and Arctic Wolf observed attempts to transfer tools and exfiltrate configuration files. The bulletin urges immediate patching to specified fixed PAN-OS versions, restricting management interface access, and following remediation guidance (including Enhanced Factory Reset for confirmed compromises).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.