logo

Another CVE (PAN-OS Zero Day)

ID: d936dad9-22bb-51e9-a366-97fa11708969

STIX ID: report--d936dad9-22bb-51e9-a366-97fa11708969

Feed Name: Zscaler Security Research Blog

Threat Score
92/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details CVE-2024-3400, a critical PAN-OS command-injection zero-day (CVSS 10.0) being actively exploited to enable unauthenticated root code execution on Palo Alto firewalls. It describes an observed attack chain—initial exploitation, persistence via Cron and tools such as a UPSTYLE Python backdoor and GOST reverse proxy, lateral movement using SMB/WinRM, theft of AD backup/NTDS.DIT and DPAPI/browser secrets, and exfiltration to an externally accessible web directory—and provides vendor mitigation guidance and affected PAN-OS versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.