CVE-2020-2034Active Exploitation(paloaltonetworks / pan-os)

LOWCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be exploited if GlobalProtect portal feature is not enabled. This issue impacts PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; all versions of PAN-OS 8.0 and PAN-OS 7.1. Prisma Access services are not impacted by this vulnerability.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
pan-os

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-28: 2Active Exploitation · 2026-02-28: 102-28
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2020-2034 — UAB Host Baltic Visit -- https://cti.loginsoft.com/ip/141.98.11.83 #Loginsoft #Cytellite #Cybersecurity #CVE20202034 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/iWvtuT4YEN

    Post summary

    The tweet references a recent detection of activity related to CVE-2020-2034 but provides no further technical or mitigation details.

    0000060
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2020-2034 — UAB Host Baltic Visit -- https://cti.loginsoft.com/ip/141.98.11.83 #Loginsoft #Cytellite #Cybersecurity #CVE20202034 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/5h3M2jd2hN

    Post summary

    Cytellite reports recent detection of activity targeting CVE-2020-2034, indicating potential active exploitation, but no further details or mitigation steps are provided.

    0000061
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os---

Explore more