Documented CVEs
7 vulnerabilities cataloged in the Hermes intelligence repository.
| Parameter | Technical Specification |
|---|---|
| Official Name | Palo Alto Networks PAN-OS |
| Vendor / Project | paloaltonetworks |
| Canonical ID | paloaltonetworks:pan-os |
| Versioning Scheme | semver |
| CPE Identifiers | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
| Overall Posture | CRITICAL |
| Recommended Safe Release | 11.2.4-h1 |
Documented CVEs
7 vulnerabilities cataloged in the Hermes intelligence repository.
CISA KEV Entries
6 flaws with confirmed active in-the-wild exploitation.
Weaponized Exploits
7 vulnerabilities with publicly available PoCs or weaponized exploit tooling.
Remediation Target
Recommended upgrade to 11.2.4-h1 to neutralize known flaws.
Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:
0 / 100
= Stable over 30d
100.0 %
= Stable over 30d
6
Active in-the-wild exploitation
| CVE | CVSS Score | EPSS Probability | CISA KEV | Affected Versions | Fixed In | Hermes Analysis |
|---|---|---|---|---|---|---|
| CVE-2024-3400 | 10 (CRITICAL) | 100.0% | CISA KEV | < v10.2.9-h1, < v11.0.4-h1, < v11.1.2-h3 | 10.2.9-h1, 11.0.4-h1, 11.1.2-h3 | Analysis β |
| CVE-2020-2021 | 10 (CRITICAL) | 97.5% | CISA KEV | v9.1.0 to v9.1.2, v9.0.0 to v9.0.8, v8.1.0 to v8.1.14 | 9.1.3, 9.0.9, 8.1.15, 10.0.0 | Analysis β |
| CVE-2026-0257 | 9.8 (CRITICAL) | 95.2% | CISA KEV | < v11.2.3, < v11.1.4, < v11.0.5, < v10.2.10 | 11.2.3, 11.1.4, 11.0.5, 10.2.10 | Analysis β |
| CVE-2026-0300 | 9.8 (CRITICAL) | 31.7% | CISA KEV | < v11.2.4, < v11.1.5, < v11.0.6, < v10.2.11 | 11.2.4, 11.1.5, 11.0.6, 10.2.11 | Analysis β |
| CVE-2021-3064 | 9.8 (CRITICAL) | 95.2% | No | v8.1.0 to v8.1.16 | 8.1.17, 9.0.0 | - |
| CVE-2024-0012 | 9.3 (CRITICAL) | 99.7% | CISA KEV | < v10.2.12-h2, < v11.0.6-h1, < v11.1.5-h1, < v11.2.4-h1 | 10.2.12-h2, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1 | Analysis β |
| CVE-2024-9474 | 6.9 (MEDIUM) | 89.2% | CISA KEV | < v10.2.12-h2, < v11.0.6-h1, < v11.1.5-h1, < v11.2.4-h1 | 10.2.12-h2, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1 | - |
Vulnerabilities impacting Palo Alto Networks PAN-OS are actively leveraged in real-world intrusion campaigns:
Are you operating Palo Alto Networks PAN-OS in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: