CVE-2018-10141Active Exploitation(paloaltonetworks / pan-os)

LOWCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • 2 total mentions across 1 day

Affected systems

Products
pan-os

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-06: 2Active Exploitation · 2026-05-06: 205-06
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2018-10141 — IP Volume inc Visit -- https://cti.loginsoft.com/ip/94.102.49.148 #Loginsoft #Cytellite #Cybersecurity #CVE201810141 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/Q4FAFohuGr

    Post summary

    Cytellite reports recent detection of exploitation of CVE‑2018‑10141 by IP Volume inc, providing no technical details or mitigation advice.

    0000026
    20 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2018-10141 — IP Volume inc Visit -- https://cti.loginsoft.com/ip/94.102.49.148 #Loginsoft #Cytellite #Cybersecurity #CVE201810141 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/zp8TvU4GX2

    Post summary

    The tweet reports that Cytellite detected activity targeting CVE‑2018‑10141, implying that the vulnerability is being exploited in the wild.

    0000025
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os---

Explore more