logo

CISA warns of critical Palo Alto Networks bug exploited in attacks

ID: 70b62e15-8db6-55da-96c5-223eb84fb89f

STIX ID: report--70b62e15-8db6-55da-96c5-223eb84fb89f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-11-07

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warns that attackers are exploiting a critical missing-authentication vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, which can allow remote admin account takeover and access to secrets; a proof-of-concept and chaining with a command-injection flaw (CVE-2024-9464) enable unauthenticated arbitrary command execution and potential PAN-OS firewall takeover, prompting patches, mitigation guidance, and inclusion in CISA's Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.