<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Palo Alto Networks</title><description>PAN-OS and GlobalProtect vulnerabilities affecting Palo Alto Networks firewalls — perimeter devices where a single command-injection flaw can mean full network compromise. Combined article + CVE feed for the Palo Alto Networks beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2017-15944 — Palo Alto Networks PAN-OS Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-15944/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-15944/</guid><description>Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-1579 — Palo Alto Networks PAN-OS Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1579/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1579/</guid><description>Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>high</category><category>cve</category></item><item><title>CVE-2020-2021 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2020-2021/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-2021/</guid><description>Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-0028 — Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2022-0028/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-0028/</guid><description>A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>high</category><category>cve</category></item><item><title>CVE-2024-0012 — Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2024-0012/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-0012/</guid><description>Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-3393 — Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability</title><link>https://0daynews.com/cve/cve-2024-3393/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-3393/</guid><description>Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>high</category><category>cve</category></item><item><title>CVE-2024-3400 — Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day</title><link>https://0daynews.com/cve/cve-2024-3400/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-3400/</guid><description>A command-injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Exploited in the wild as a zero-day before a patch was available.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-5910 — Palo Alto Networks Expedition Missing Authentication Vulnerability</title><link>https://0daynews.com/cve/cve-2024-5910/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-5910/</guid><description>Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-9463 — Palo Alto Networks Expedition OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-9463/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-9463/</guid><description>Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>high</category><category>cve</category></item><item><title>CVE-2024-9465 — Palo Alto Networks Expedition SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-9465/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-9465/</guid><description>Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-9474 — Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-9474/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-9474/</guid><description>Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>high</category><category>cve</category></item><item><title>CVE-2025-0108 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2025-0108/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-0108/</guid><description>Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-0111 — Palo Alto Networks PAN-OS File Read Vulnerability</title><link>https://0daynews.com/cve/cve-2025-0111/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-0111/</guid><description>Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-0257 — PAN-OS GlobalProtect authentication bypass</title><link>https://0daynews.com/cve/cve-2026-0257/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-0257/</guid><description>PAN-OS GlobalProtect portal and gateway authentication bypass allowing an unauthorized VPN connection under a specific authentication-override-cookie and certificate configuration. Actively exploited by Qilin ransomware.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-0300 — Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability</title><link>https://0daynews.com/cve/cve-2026-0300/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-0300/</guid><description>Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>critical</category><category>cve</category></item><item><title>Qilin exploits PAN-OS GlobalProtect CVE-2026-0257</title><link>https://0daynews.com/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation/</guid><description>Arctic Wolf documents Qilin ransomware breaching networks through a two-month-old PAN-OS GlobalProtect authentication bypass, and assesses with moderate confidence that intrusions are ongoing.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>article</category></item><item><title>PAN-OS GlobalProtect Zero-Day Gave Attackers Root</title><link>https://0daynews.com/articles/2026-06-27-pan-os-globalprotect-command-injection-zero-day/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-06-27-pan-os-globalprotect-command-injection-zero-day/</guid><description>CVE-2024-3400, a maximum-severity command-injection flaw in Palo Alto Networks&apos; PAN-OS GlobalProtect feature, was exploited in the wild before a patch existed — handing attackers root access to the perimeter firewall.</description><pubDate>Sat, 27 Jun 2026 13:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>article</category></item></channel></rss>