logo

CISA warns of more Palo Alto Networks bugs exploited in attacks

ID: fa2c790f-7261-5579-aafd-47765cc26448

STIX ID: report--fa2c790f-7261-5579-aafd-47765cc26448

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Critical vulnerabilities in Palo Alto Networks Expedition are being actively exploited.** Two unauthenticated flaws (a command injection and an SQL injection) allow attackers to execute arbitrary commands as root and access or modify Expedition database contents—exposing usernames, cleartext passwords, device configurations, and API keys—potentially enabling firewall account takeover. CISA added the CVEs to its Known Exploited Vulnerabilities catalog and mandated federal patching; Palo Alto released fixes in Expedition 1.2.96+ and recommends restricting access and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.