logo

Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack

ID: 165b8851-3825-5205-acb8-ee5882c40a4c

STIX ID: report--165b8851-3825-5205-acb8-ee5882c40a4c

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-04-12

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks warns of CVE-2024-3400, a critical (CVSS 10.0) command-injection zero-day in PAN-OS GlobalProtect gateways that can allow unauthenticated remote root code execution; it is being actively exploited in the wild. The issue affects PAN-OS versions <11.1.2-h3, <11.0.4-h1, and <10.2.9-h1 when both GlobalProtect gateway and device telemetry features are enabled, with mitigations (Threat ID 95187) recommended and vendor fixes expected on April 14, 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.