| 4.5 | CVE-2025-4615
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access  | None None < 11.2.8 < 11.1.10-h7 < 10.2.17 None  | All All >= 11.2.8 >= 11.1.10-h7 >= 10.2.17 All  | 2025-10-08 | 2025-10-08 | 
| 1.1 | CVE-2025-4614
PAN-OS: Session Token Disclosure Vulnerability | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access  | None None < 11.2.8 < 11.1.10-h7 < 10.2.17 None  | All All >= 11.2.8 >= 11.1.10-h7 >= 10.2.17 All  | 2025-10-08 | 2025-10-08 | 
| 3.3 | CVE-2025-2182
PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK) | Cloud NGFW PAN-OS PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None None on devices other than PA-7500 < 11.2.8 on PA-7500 < 11.1.10 on PA-7500 None on PA-7500 None on PA-7500 None  | All All on devices other than PA-7500 >= 11.2.8 on PA-7500 >= 11.1.10 on PA-7500 All on PA-7500 All on PA-7500 All  | 2025-08-13 | 2025-08-13 | 
| 2.3 | CVE-2025-4229
PAN-OS: Traffic Information Disclosure Vulnerability | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.7 < 11.1.10 < 10.2.16-h1, < 10.2.17 < 10.1.14-h16 None  | All >= 11.2.7 >= 11.1.10 >= 10.2.16-h1, >= 10.2.17 [ETA: Aug 2025] >= 10.1.14-h16 All  | 2025-06-11 | 2025-06-30 | 
| 5.7 | CVE-2025-4230
PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.6 < 11.1.6-h14, < 11.1.10 < 10.2.10-h27 < 10.1.14-h15 None  | All >= 11.2.6 >= 11.1.6-h14, >= 11.1.10 >= 10.2.10-h27 >= 10.1.14-h15 All  | 2025-06-11 | 2025-06-30 | 
| 2 | CVE-2025-0133
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | All < 11.2.4-h9, < 11.2.7 < 11.1.6-h14, < 11.1.10-h1 < 10.2.16-h1 All All  | None (See Mitigations and Workarounds) >= 11.2.4-h9, >= 11.2.7 >= 11.1.6-h14, >= 11.1.10-h1 >= 10.2.16-h1 None None (See Mitigations and Workarounds)  | 2025-05-14 | 2025-07-09 | 
| 1.1 | CVE-2025-0137
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.5 < 11.1.6-h14, < 11.1.8 < 10.2.13 < 10.1.14-h14 None  | All >= 11.2.5 >= 11.1.6-h14, >= 11.1.8 >= 10.2.13 >= 10.1.14-h14 All  | 2025-05-14 | 2025-07-11 | 
| 1.3 | CVE-2025-0136
PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None None < 11.1.5 < 11.0.7 < 10.2.11 < 10.1.14-h14 None  | All All >= 11.1.5 >= 11.0.7 >= 10.2.11 >= 10.1.14-h14 All  | 2025-05-14 | 2025-05-14 | 
| 4.6 | CVE-2025-0130
PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.5 < 11.1.6-h1, < 11.1.7-h2, < 11.1.8 None None None  | All >= 11.2.5 >= 11.1.6-h1, >= 11.1.7-h2, >= 11.1.8 All All All  | 2025-05-14 | 2025-05-14 | 
| 5.6 | CVE-2025-0126
PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.3 < 11.1.5 < 11.0.6 < 10.2.4-h25, < 10.2.9-h13, < 10.2.10-h6, < 10.2.11 < 10.1.14-h11 < 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS  | All >= 11.2.3 >= 11.1.5 >= 11.0.6 >= 10.2.4-h25, >= 10.2.9-h13, >= 10.2.10-h6, >= 10.2.11 >= 10.1.14-h11 >= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS  | 2025-04-09 | 2025-04-09 | 
| 2 | CVE-2025-0124
PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | All < 11.2.1 < 11.1.5 < 11.0.6 < 10.2.10 < 10.1.14-h11 None  | None (ETA end of April) >= 11.2.1 >= 11.1.5 >= 11.0.6 >= 10.2.10 >= 10.1.14-h11 All  | 2025-04-09 | 2025-04-09 | 
| 1.9 | CVE-2025-0123
PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.6 < 11.1.6-h10, < 11.1.8 < 10.2.10-h21, < 10.2.15 < 10.1.14-h13 None  | All >= 11.2.6 >= 11.1.6-h10, >= 11.1.8 >= 10.2.10-h21, >= 10.2.15 >= 10.1.14-h13 All  | 2025-04-09 | 2025-07-11 | 
| 6.6 | CVE-2025-0128
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None on PAN-OS < 11.2.3 < 11.1.5 < 11.0.6 < 10.2.10-h17 < 10.1.14-h11 < 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS  | All on PAN-OS >= 11.2.3 >= 11.1.5 >= 11.0.6 >= 10.2.10-h17 >= 10.1.14-h11 >= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS  | 2025-04-09 | 2025-04-09 | 
| 4.4 | CVE-2025-0125
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.5 < 11.1.5 < 11.0.6 < 10.2.10-h19, < 10.2.11 < 10.1.14-h11 None  | All >= 11.2.5 >= 11.1.5 >= 11.0.6 >= 10.2.10-h19, >= 10.2.11 >= 10.1.14-h11 All  | 2025-04-09 | 2025-06-12 | 
| 4.3 | CVE-2025-0115
PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.3 < 11.1.4-h17, < 11.1.5 < 11.0.6 < 10.2.10-h18, < 10.2.11 < 10.1.14-h11 None  | All >= 11.2.3 >= 11.1.4-h17, >= 11.1.5 >= 11.0.6 >= 10.2.10-h18, >= 10.2.11 >= 10.1.14-h11 All  | 2025-03-12 | 2025-06-12 | 
| 4.3 | CVE-2025-0116
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.5 < 11.1.4-h17, < 11.1.6-h6, < 11.1.8 < 10.2.10-h17, < 10.2.13-h5, < 10.2.14 < 10.1.14-h11 None  | All >= 11.2.5 >= 11.1.4-h17, >= 11.1.6-h6, >= 11.1.8 >= 10.2.10-h17, >= 10.2.13-h5, >= 10.2.14 >= 10.1.14-h11 All  | 2025-03-12 | 2025-04-04 | 
| 8.8 | CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.4-h4, < 11.2.5 < 11.1.2-h18, < 11.1.4-h13, < 11.1.6-h1 < 10.2.7-h24, < 10.2.8-h21, < 10.2.9-h21, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3 < 10.1.14-h9 None  | All >= 11.2.4-h4, >= 11.2.5 >= 11.1.2-h18, >= 11.1.4-h13, >= 11.1.6-h1 >= 10.2.7-h24, >= 10.2.8-h21, >= 10.2.9-h21, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3 >= 10.1.14-h9 All  | 2025-02-12 | 2025-03-06 | 
| 5.5 | CVE-2025-0109
PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.4-h4, < 11.2.5 < 11.1.2-h18, < 11.1.4-h13, < 11.1.6-h1 < 10.2.7-h24, < 10.2.8-h21, < 10.2.9-h21, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3 < 10.1.14-h9 None  | All >= 11.2.4-h4, >= 11.2.5 >= 11.1.2-h18, >= 11.1.4-h13, >= 11.1.6-h1 >= 10.2.7-h24, >= 10.2.8-h21, >= 10.2.9-h21, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3 >= 10.1.14-h9 All  | 2025-02-12 | 2025-03-06 | 
| 7.1 | CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.4-h4, < 11.2.5 < 11.1.2-h18, < 11.1.4-h13, < 11.1.6-h1 < 10.2.7-h24, < 10.2.8-h21, < 10.2.9-h21, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3 < 10.1.14-h9 None  | All >= 11.2.4-h4, >= 11.2.5 >= 11.1.2-h18, >= 11.1.4-h13, >= 11.1.6-h1 >= 10.2.7-h24, >= 10.2.8-h21, >= 10.2.9-h21, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3 >= 10.1.14-h9 All  | 2025-02-12 | 2025-03-06 | 
| 8.7 | CVE-2024-3393
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | Cloud NGFW PAN-OS PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 Prisma Access  | None None on Panorama < 11.2.3 < 11.1.2-h16, < 11.1.3-h13, < 11.1.4-h7, < 11.1.5 >= 10.2.8, < 10.2.8-h19, < 10.2.9-h19, < 10.2.10-h12, < 10.2.11-h10, < 10.2.12-h4, < 10.2.13-h2, < 10.2.14 >= 10.1.14, < 10.1.14-h8, < 10.1.15 None None >= 10.2.8 on PAN-OS, < 10.2.9-h19 on PAN-OS, < 10.2.10-h12 on PAN-OS, < 11.2.3 on PAN-OS  | All All on Panorama >= 11.2.3 >= 11.1.2-h16, >= 11.1.3-h13, >= 11.1.4-h7, >= 11.1.5 < 10.2.8, >= 10.2.8-h19, >= 10.2.9-h19, >= 10.2.10-h12, >= 10.2.11-h10, >= 10.2.12-h4, >= 10.2.13-h2, >= 10.2.14 < 10.1.14, >= 10.1.14-h8, >= 10.1.15 All All < 10.2.8 on PAN-OS, >= 10.2.9-h19 on PAN-OS, >= 10.2.10-h12 on PAN-OS, >= 11.2.3 on PAN-OS  | 2024-12-27 | 2025-01-30 | 
| 6.9 | CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.0-h1, < 11.2.1-h1, < 11.2.2-h2, < 11.2.3-h3, < 11.2.4-h1 < 11.1.0-h4, < 11.1.1-h2, < 11.1.2-h15, < 11.1.3-h11, < 11.1.4-h7, < 11.1.5-h1 < 11.0.0-h4, < 11.0.1-h5, < 11.0.2-h5, < 11.0.3-h13, < 11.0.4-h6, < 11.0.5-h2, < 11.0.6-h1 < 10.2.0-h4, < 10.2.1-h3, < 10.2.2-h6, < 10.2.3-h14, < 10.2.4-h32, < 10.2.5-h9, < 10.2.6-h6, < 10.2.7-h18, < 10.2.8-h15, < 10.2.9-h16, < 10.2.10-h9, < 10.2.11-h6, < 10.2.12-h2 < 10.1.3-h4, < 10.1.6-h9, < 10.1.8-h8, < 10.1.9-h14, < 10.1.10-h9, < 10.1.11-h10, < 10.1.12-h3, < 10.1.13-h5, < 10.1.14-h6 None  | All >= 11.2.0-h1, >= 11.2.1-h1, >= 11.2.2-h2, >= 11.2.3-h3, >= 11.2.4-h1 >= 11.1.0-h4, >= 11.1.1-h2, >= 11.1.2-h15, >= 11.1.3-h11, >= 11.1.4-h7, >= 11.1.5-h1 >= 11.0.0-h4, >= 11.0.1-h5, >= 11.0.2-h5, >= 11.0.3-h13, >= 11.0.4-h6, >= 11.0.5-h2, >= 11.0.6-h1 >= 10.2.0-h4, >= 10.2.1-h3, >= 10.2.2-h6, >= 10.2.3-h14, >= 10.2.4-h32, >= 10.2.5-h9, >= 10.2.6-h6, >= 10.2.7-h18, >= 10.2.8-h15, >= 10.2.9-h16, >= 10.2.10-h9, >= 10.2.11-h6, >= 10.2.12-h2 >= 10.1.3-h4, >= 10.1.6-h9, >= 10.1.8-h8, >= 10.1.9-h14, >= 10.1.10-h9, >= 10.1.11-h10, >= 10.1.12-h3, >= 10.1.13-h5, >= 10.1.14-h6 All  | 2024-11-18 | 2024-11-21 | 
| 9.3 | CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.0-h1, < 11.2.1-h1, < 11.2.2-h2, < 11.2.3-h3, < 11.2.4-h1 < 11.1.0-h4, < 11.1.1-h2, < 11.1.2-h15, < 11.1.3-h11, < 11.1.4-h7, < 11.1.5-h1 < 11.0.0-h4, <  11.0.1-h5, < 11.0.2-h5, < 11.0.3-h13, < 11.0.4-h6, <  11.0.5-h2, < 11.0.6-h1 < 10.2.0-h4, < 10.2.1-h3, <  10.2.2-h6, < 10.2.3-h14, < 10.2.4-h32, < 10.2.5-h9, < 10.2.6-h6, < 10.2.7-h18, < 10.2.8-h15, < 10.2.9-h16, <  10.2.10-h9, < 10.2.11-h6, < 10.2.12-h2 None None  | All >= 11.2.0-h1, >= 11.2.1-h1, >= 11.2.2-h2, >= 11.2.3-h3, >= 11.2.4-h1 >= 11.1.0-h4, >= 11.1.1-h2, >= 11.1.2-h15, >= 11.1.3-h11, >= 11.1.4-h7, >= 11.1.5-h1 >= 11.0.0-h4, >=  11.0.1-h5, >= 11.0.2-h5, >= 11.0.3-h13, >= 11.0.4-h6, >=  11.0.5-h2, >= 11.0.6-h1 >= 10.2.0-h4, >= 10.2.1-h3, >=  10.2.2-h6, >= 10.2.3-h14, >= 10.2.4-h32, >= 10.2.5-h9, >= 10.2.6-h6, >= 10.2.7-h18, >= 10.2.8-h15, >= 10.2.9-h16, >=  10.2.10-h9, >= 10.2.11-h6, >= 10.2.12-h2 All All  | 2024-11-18 | 2025-03-03 | 
| 4.3 | CVE-2024-2552
PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI) | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.4 < 11.1.4-h9, < 11.1.5 < 11.0.6 < 10.2.7-h21, < 10.2.8-h18, < 10.2.9-h18, < 10.2.10-h10, < 10.2.11-h9, < 10.2.12 None None  | All >= 11.2.4 >= 11.1.4-h9, >= 11.1.5 >= 11.0.6 >= 10.2.7-h21, >= 10.2.8-h18, >= 10.2.9-h18, >= 10.2.10-h10, >= 10.2.11-h9, >= 10.2.12 All All  | 2024-11-13 | 2025-01-06 | 
| 6.6 | CVE-2024-9472
PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Traffic | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None < 11.2.2-h3, < 11.2.3 < 11.1.2-h14, < 11.1.3-h10 None < 10.2.7-h16, < 10.2.8-h13, < 10.2.9-h14, < 10.2.10-h7, < 10.2.11-h4 None None  | All >= 11.2.2-h3, >= 11.2.3 >= 11.1.2-h14, >= 11.1.3-h10 All >= 10.2.7-h16, >= 10.2.8-h13, >= 10.2.9-h14, >= 10.2.10-h7, >= 10.2.11-h4 All All  | 2024-11-13 | 2024-11-13 | 
| 1 | CVE-2024-5920
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access  | None None < 11.1.4 < 11.0.6 < 10.2.7-h24, < 10.2.10-h14, < 10.2.11 < 10.1.14 None  | All All >= 11.1.4 >= 11.0.6 >= 10.2.7-h24, >= 10.2.10-h14, >= 10.2.11 >= 10.1.14 All  | 2024-11-13 | 2025-04-30 |