logo

Palo Alto Networks patches two firewall zero-days used in attacks

ID: f6296317-9817-5e3e-92d9-0311e23be512

STIX ID: report--f6296317-9817-5e3e-92d9-0311e23be512

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-11-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Palo Alto Networks released fixes for two actively exploited PAN-OS zero-days — CVE-2024-0012 (management web interface authentication bypass enabling administrator access) and CVE-2024-9474 (privilege escalation to root) — with observed exploitation against internet-exposed management interfaces, thousands of exposed devices reported by Shadowserver/Shodan, published IOCs, and CISA adding the issues to its Known Exploited Vulnerabilities Catalog and mandating rapid patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.