Skip to content

Palo Alto Networks PAN-OS β€” Security Intelligence & Vulnerability Profile


ParameterTechnical Specification
Official NamePalo Alto Networks PAN-OS
Vendor / Projectpaloaltonetworks
Canonical IDpaloaltonetworks:pan-os
Versioning Schemesemver
CPE Identifierscpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Overall PostureCRITICAL
Recommended Safe Release11.2.4-h1

Documented CVEs

7 vulnerabilities cataloged in the Hermes intelligence repository.

CISA KEV Entries

6 flaws with confirmed active in-the-wild exploitation.

Weaponized Exploits

7 vulnerabilities with publicly available PoCs or weaponized exploit tooling.

Remediation Target

Recommended upgrade to 11.2.4-h1 to neutralize known flaws.


Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:

Current HTS Score

0 / 100

= Stable over 30d

Max EPSS (Exploitation)

100.0 %

= Stable over 30d

CISA KEV Activity

6

Active in-the-wild exploitation

HTS Trend Curve (D-30 β†’ Today)2026-08-12 β†’ 2026-09-10
2026-09-10: CVE: CVE-2026-0300

3. Vulnerability History & Version Applicability Matrix

Section titled β€œ3. Vulnerability History & Version Applicability Matrix”
CVECVSS ScoreEPSS ProbabilityCISA KEVAffected VersionsFixed InHermes Analysis
CVE-2024-340010 (CRITICAL)100.0%CISA KEV< v10.2.9-h1, < v11.0.4-h1, < v11.1.2-h310.2.9-h1, 11.0.4-h1, 11.1.2-h3Analysis β†’
CVE-2020-202110 (CRITICAL)97.5%CISA KEVv9.1.0 to v9.1.2, v9.0.0 to v9.0.8, v8.1.0 to v8.1.149.1.3, 9.0.9, 8.1.15, 10.0.0Analysis β†’
CVE-2026-02579.8 (CRITICAL)95.2%CISA KEV< v11.2.3, < v11.1.4, < v11.0.5, < v10.2.1011.2.3, 11.1.4, 11.0.5, 10.2.10Analysis β†’
CVE-2026-03009.8 (CRITICAL)31.7%CISA KEV< v11.2.4, < v11.1.5, < v11.0.6, < v10.2.1111.2.4, 11.1.5, 11.0.6, 10.2.11Analysis β†’
CVE-2021-30649.8 (CRITICAL)95.2%Nov8.1.0 to v8.1.168.1.17, 9.0.0-
CVE-2024-00129.3 (CRITICAL)99.7%CISA KEV< v10.2.12-h2, < v11.0.6-h1, < v11.1.5-h1, < v11.2.4-h110.2.12-h2, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1Analysis β†’
CVE-2024-94746.9 (MEDIUM)89.2%CISA KEV< v10.2.12-h2, < v11.0.6-h1, < v11.1.5-h1, < v11.2.4-h110.2.12-h2, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1-

Vulnerabilities impacting Palo Alto Networks PAN-OS are actively leveraged in real-world intrusion campaigns:


Are you operating Palo Alto Networks PAN-OS in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: