Hackers exploit authentication bypass in Palo Alto Networks PAN-OS
ID: 335a16db-5a23-5b15-975a-abe335618854
STIX ID: report--335a16db-5a23-5b15-975a-abe335618854
Feed Name: Bleeping Computer
A high-severity PAN-OS vulnerability (CVE-2025-0108) allows unauthenticated attackers to bypass the web management interface authentication via an Nginx/Apache path confusion. Palo Alto Networks released patches on Feb 12, 2025 and urged upgrades; researchers published a PoC and GreyNoise has logged exploitation attempts beginning Feb 13, while researchers report ~4,400 exposed management interfaces—organizations are advised to apply updates and restrict management access immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
