logo

Palo Alto Firewall Vulnerability (CVE-2025-0108) Under Attack – Are You at Risk?

ID: b758740a-5995-5468-8420-e671a41cbcca

STIX ID: report--b758740a-5995-5468-8420-e671a41cbcca

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2025-02-14

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2025-0108 is a PAN-OS authentication bypass (CVSS 7.8) caused by Nginx/Apache path normalization differences that can allow unauthenticated execution of specific PHP scripts on the firewall management interface; active exploitation has been observed (tracked by GreyNoise), Palo Alto confirmed attacks and released patches, and CISA added the issue to its KEV catalog—organizations should immediately apply the provided PAN-OS updates and restrict management access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.