Palo Alto Networks warns of PAN-OS firewall zero-day used in attacks
ID: 7e4ed338-d295-58d6-a858-c41487f7ed7a
STIX ID: report--7e4ed338-d295-58d6-a858-c41487f7ed7a
Feed Name: Bleeping Computer
Palo Alto Networks warns of an actively exploited, critical command-injection zero-day (CVE-2024-3400, CVSS 10.0) in PAN-OS GlobalProtect when device telemetry is enabled, affecting PAN-OS 10.2, 11.0 and 11.1. Volexity discovered the flaw and researchers estimate ~82,000 potentially exposed devices; Palo Alto published hotfix releases and mitigation steps (including Threat ID 95187 and disabling telemetry, though telemetry disabling was later reported ineffective). CISA added the CVE to its Known Exploited Vulnerabilities catalog and set a patching deadline for federal agencies, so affected organizations are urged to apply vendor updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
