Palo Alto Networks Security Advisories

1 - 25 of 149
VersionsAffectedUnaffected
6.6CVE-2025-4619 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None
< 11.2.2-h2, < 11.2.3-h6, < 11.2.4-h4, < 11.2.5
>= 11.1.2-h9, < 11.1.2-h18, >= 11.1.3-h2, >= 11.1.4-h4, < 11.1.4-h13, < 11.1.6-h1, < 11.1.7
>= 10.2.4-h25, >= 10.2.7-h11, < 10.2.7-h24, >= 10.2.8-h10, < 10.2.8-h21, >= 10.2.9-h6, < 10.2.9-h21, >= 10.2.10-h2, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3, < 10.2.14
None
>= 10.2.4-h25 on PAN-OS, < 10.2.10-h14 on PAN-OS, < 11.2.4-h4 on PAN-OS
All
All
>= 11.2.2-h2, >= 11.2.3-h6, >= 11.2.4-h4, >= 11.2.5
< 11.1.2-h9, >= 11.1.2-h18, < 11.1.3-h2, < 11.1.4-h4, >= 11.1.4-h13, >= 11.1.6-h1, >= 11.1.7
< 10.2.4-h25, < 10.2.7-h11, >= 10.2.7-h24, < 10.2.8-h10, >= 10.2.8-h21, < 10.2.9-h6, >= 10.2.9-h21, < 10.2.10-h2, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3, >= 10.2.14
All
< 10.2.4-h25 on PAN-OS, >= 10.2.10-h14 on PAN-OS, >= 11.2.4-h4 on PAN-OS
2025-11-122025-11-12
4.5CVE-2025-4615 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
None
< 11.2.8
< 11.1.6-h21, < 11.1.10-h7
< 10.2.17
None
All
All
>= 11.2.8
>= 11.1.6-h21, >= 11.1.10-h7
>= 10.2.17
All
2025-10-082025-11-11
1.1CVE-2025-4614 PAN-OS: Session Token Disclosure Vulnerability
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
None
< 11.2.8
< 11.1.6-h21
< 10.2.17
None
All
All
>= 11.2.8
>= 11.1.6-h21
>= 10.2.17
All
2025-10-082025-10-08
3.3CVE-2025-2182 PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)
Cloud NGFW
PAN-OS
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None on devices other than PA-7500
< 11.2.8 on PA-7500
< 11.1.10 on PA-7500
None on PA-7500
None on PA-7500
None
All
All on devices other than PA-7500
>= 11.2.8 on PA-7500
>= 11.1.10 on PA-7500
All on PA-7500
All on PA-7500
All
2025-08-132025-08-13
4.5CVE-2025-2183 GlobalProtect App: Improper Certificate Validation Leads to Privilege Escalation
Global Protect UWP App
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
None
None on Android, None on iOS, None on macOS
< 6.3.3-h2 (6.3.3-c676) on Windows, < 6.3.3 on Linux
< 6.2.8-h3 (6.2.8-c263) on Windows, All on Linux
All on Windows, All on Linux
< 6.0.12 on Windows, All on Linux
All
All on Android, All on iOS, All on macOS
>= 6.3.3-h2 (6.3.3-c676) on Windows*, >= 6.3.3 on Linux
>= 6.2.8-h3 (6.2.8-c263) on Windows*, None on Linux
None on Windows, None on Linux
>= 6.0.12 on Windows*, None on Linux
2025-08-132025-08-13
4.3CVE-2025-2179 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App
GlobalProtect App
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on Chrome OS, None on iOS, None on Windows, None on macOS
< 6.2.9 on Linux
All on Linux
All on Linux
None
All on Android, All on Chrome OS, All on iOS, All on Windows, All on macOS
>= 6.2.9 on Linux
None on Linux
None on Linux
All
2025-07-282025-07-28
4.3CVE-2025-0140 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on Chrome OS, None on iOS, None on Windows, None on Linux
< 6.3.3-h1 (6.3.3-c650) on macOS
< 6.2.8-h2 (6.2.8-c243) on macOS
All on macOS
< 6.0.12 on macOS
None
All on Android, All on Chrome OS, All on iOS, All on Windows, All on Linux
>= 6.3.3-h1 (6.3.3-c650) on macOS
>= 6.2.8-h2 (6.2.8-c243) on macOS
None on macOS
>= 6.0.12 on macOS
All
2025-07-092025-07-28
5.7CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on Chrome OS, None on iOS
< 6.3.3-h1 (6.3.3-c650) on macOS, < 6.3.3-h1 (6.3.3-c650) on Windows
< 6.2.8-h2 (6.2.8-c243) on macOS, < 6.2.8-h2 (6.2.8-c243) on Windows, < 6.2.8 on Linux
All on macOS, All on Windows, All on Linux
< 6.0.12 on macOS, < 6.0.12 on Windows, All on Linux
None
All on Android, All on Chrome OS, All on iOS
>= 6.3.3-h1 (6.3.3-c650) on macOS, >= 6.3.3-h1 (6.3.3-c650) on Windows
>= 6.2.8-h2 (6.2.8-c243) on macOS, >= 6.2.8-h2 (6.2.8-c243) on Windows, >= 6.2.8 on Linux
None on macOS, None on Windows, None on Linux
>= 6.0.12 on macOS, >= 6.0.12 on Windows, None on Linux
All
2025-07-092025-07-18
5.7CVE-2025-4232 GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
None on Windows, Linux, Android, iOS, Chrome OS
< 6.3.3 on macOS
< 6.2.8-h2 [6.2.8-c243] on macOS
All on macOS
< 6.0.12 on macOS
All on Windows, Linux, Android, iOS, Chrome OS
>= 6.3.3 on macOS
>= 6.2.8-h2 [6.2.8-c243] on macOS
None on macOS
>= 6.0.12 on macOS
2025-06-112025-07-16
6.1CVE-2025-4231 PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None
None
< 11.0.3
< 10.2.8
All
None
All
All
All
>= 11.0.3
>= 10.2.8
None
All
2025-06-112025-06-11
5.7CVE-2025-4230 PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.6
< 11.1.6-h14, < 11.1.10
< 10.2.10-h27
< 10.1.14-h15
None
All
>= 11.2.6
>= 11.1.6-h14, >= 11.1.10
>= 10.2.10-h27
>= 10.1.14-h15
All
2025-06-112025-06-30
2.3CVE-2025-4229 PAN-OS: Traffic Information Disclosure Vulnerability
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.7
< 11.1.10
< 10.2.16-h1, < 10.2.17
< 10.1.14-h16
None
All
>= 11.2.7
>= 11.1.10
>= 10.2.16-h1, >= 10.2.17 [ETA: Aug 2025]
>= 10.1.14-h16
All
2025-06-112025-06-30
0.3CVE-2025-4227 GlobalProtect App: Interception in Endpoint Traffic Policy Enforcement
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
None on Linux, Android, iOS, Chrome OS, UWP ¹
< 6.3.3-h1 [6.3.3-c650] on Windows, macOS
< 6.2.8-h2 [6.2.8-c243] on Windows, macOS
All on Windows, macOS
All on Windows, macOS
All on Linux, Android, iOS, Chrome OS, UWP ¹
>= 6.3.3-h1 [6.3.3-c650] on Windows, macOS
>= 6.2.8-h2 [6.2.8-c243] on Windows, macOS
None on Windows, macOS
None on Windows, macOS
2025-06-112025-06-13
4.6CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.6-h1, < 11.1.7-h2, < 11.1.8
None
None
None
All
>= 11.2.5
>= 11.1.6-h1, >= 11.1.7-h2, >= 11.1.8
All
All
All
2025-05-142025-05-14
2CVE-2025-0133 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
All
< 11.2.4-h9, < 11.2.7
< 11.1.6-h14, < 11.1.10-h1
< 10.2.16-h1
All
All
None (See Mitigations and Workarounds)
>= 11.2.4-h9, >= 11.2.7
>= 11.1.6-h14, >= 11.1.10-h1
>= 10.2.16-h1
None
None (See Mitigations and Workarounds)
2025-05-142025-07-09
1.9CVE-2025-0135 GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on Chrome OS, None on iOS, None on Windows, None on Linux
< 6.3.3-h2 (6.3.3-c676) on macOS
< 6.2.8-h3 (6.2.8-c263) on macOS
All on macOS
< 6.0.12 on macOS
None
All on Android, All on Chrome OS, All on iOS, All on Windows, All on Linux
>= 6.3.3-h2 (6.3.3-c676) on macOS
>= 6.2.8-h3 (6.2.8-c263) on macOS
None on macOS
>= 6.0.12 on macOS
All
2025-05-142025-07-31
1.3CVE-2025-0136 PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None
< 11.1.5
< 11.0.7
< 10.2.11
< 10.1.14-h14
None
All
All
>= 11.1.5
>= 11.0.7
>= 10.2.11
>= 10.1.14-h14
All
2025-05-142025-05-14
1.1CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.6-h14, < 11.1.8
< 10.2.13
< 10.1.14-h14
None
All
>= 11.2.5
>= 11.1.6-h14, >= 11.1.8
>= 10.2.13
>= 10.1.14-h14
All
2025-05-142025-07-11
4CVE-2025-0120 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on macOS, None on Linux, None on iOS, None on Android, None on Chrome OS
< 6.3.3 on Windows
< 6.2.7-1077 on Windows, < 6.2.8 on Windows
All on Windows
< 6.0.12 on Windows
None
All on macOS, All on Linux, All on iOS, All on Android, All on Chrome OS
>= 6.3.3 on Windows
>= 6.2.7-1077 on Windows, >= 6.2.8 on Windows
None on Windows
>= 6.0.12 on Windows
All
2025-04-092025-05-02
1.9CVE-2025-0123 PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.6
< 11.1.6-h10, < 11.1.8
< 10.2.10-h21, < 10.2.15
< 10.1.14-h13
None
All
>= 11.2.6
>= 11.1.6-h10, >= 11.1.8
>= 10.2.10-h21, >= 10.2.15
>= 10.1.14-h13
All
2025-04-092025-07-11
2CVE-2025-0124 PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
All
< 11.2.1
< 11.1.5
< 11.0.6
< 10.2.10
< 10.1.14-h11
None
None (ETA end of April)
>= 11.2.1
>= 11.1.5
>= 11.0.6
>= 10.2.10
>= 10.1.14-h11
All
2025-04-092025-04-09
4.4CVE-2025-0125 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.5
< 11.0.6
< 10.2.10-h19, < 10.2.11
< 10.1.14-h11
None
All
>= 11.2.5
>= 11.1.5
>= 11.0.6
>= 10.2.10-h19, >= 10.2.11
>= 10.1.14-h11
All
2025-04-092025-06-12
5.6CVE-2025-0126 PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.3
< 11.1.5
< 11.0.6
< 10.2.4-h25, < 10.2.9-h13, < 10.2.10-h6, < 10.2.11
< 10.1.14-h11
< 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS
All
>= 11.2.3
>= 11.1.5
>= 11.0.6
>= 10.2.4-h25, >= 10.2.9-h13, >= 10.2.10-h6, >= 10.2.11
>= 10.1.14-h11
>= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS
2025-04-092025-04-09
4CVE-2025-0127 PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None on VM-Series
None on VM-Series
< 11.0.4 on VM-Series
< 10.2.9 on VM-Series
< 10.1.14-h13 on VM-Series
None
All
All on VM-Series
All on VM-Series
>= 11.0.4 on VM-Series
>= 10.2.9 on VM-Series
>= 10.1.14-h13 on VM-Series
All
2025-04-092025-04-09
6.6CVE-2025-0128 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None on PAN-OS
< 11.2.3
< 11.1.5
< 11.0.6
< 10.2.10-h17
< 10.1.14-h11
< 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS
All on PAN-OS
>= 11.2.3
>= 11.1.5
>= 11.0.6
>= 10.2.10-h17
>= 10.1.14-h11
>= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS
2025-04-092025-04-09
1 - 25 of 149 Download
© 2025 Palo Alto Networks, Inc. All rights reserved.