Palo Alto Firewall Vulnerability (CVE-2025-0108) Under Attack – Are You at Risk?
ID: b758740a-5995-5468-8420-e671a41cbcca
STIX ID: report--b758740a-5995-5468-8420-e671a41cbcca
Feed Name: SOCRadar Blog
Threat Score
CVE-2025-0108 is a PAN-OS authentication bypass (CVSS 7.8) caused by Nginx/Apache path normalization differences that can allow unauthenticated execution of specific PHP scripts on the firewall management interface; active exploitation has been observed (tracked by GreyNoise), Palo Alto confirmed attacks and released patches, and CISA added the issue to its KEV catalog—organizations should immediately apply the provided PAN-OS updates and restrict management access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
