CVE-2019-1579Active Exploitation(paloaltonetworks / pan-os)

LOWCVSS 8.1 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-07-10. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-134

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
pan-os

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Active Exploitation · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. GlobalProtect CVE-2019-1579 (unauth RCE, CISA KEV) drew only isolated activity through late June, then more than 120 malicious hosts probed it on 06 July, almost all from a single hosting network. Separately, two coordinated hosting fleets ran the week's highest-volume web exploitation, roughly 7.5M connection attempts. Access our public preview At The Edge Clear: https://www.greynoise.io/resources/at-the-edge-clear-070626 GreyNoise customers get the full weekly brief.

    Post summary

    The post reports active exploitation of CVE-2019-1579 on Palo Alto GlobalProtect, noting over 120 malicious probes and millions of connection attempts, with no PoC, code, or patch reference provided.

    3402673.9K
    29.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os---

Explore more