CVE-2024-0012Active Exploitation(paloaltonetworks / pan-os)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 10 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 10 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-05-01); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Products
pan-os

31 versions affected across 1 product

Deep dive

Activity timeline12 mentions / 7d
01345Mentions · 2026-01-28: 2Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-05-01: 5Mentions · 2026-05-07: 1Mentions · 2026-08-10: 1Mentions · 2026-10-06: 1Active Exploitation · 2026-01-28: 2Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-05-01: 5Active Exploitation · 2026-08-10: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-01: 3Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-05-01: 301-2804-2404-2605-0105-0708-1010-06
Signal classification2 categories
Active Exploitation
1090.9%
General
19.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-282
Active Exploitation2
2026-04-241
Active Exploitation1
2026-04-261
Active Exploitation1
2026-05-015
Active Exploitation5
2026-05-071
General1
2026-08-101
Active Exploitation1
Full discourse12 posts
  • Cyb3rVolt3x@AndraxPentester

    CVE-2024-9474 scores 6.9 Medium under CVSS 4.0. It needs PAN-OS admin first. CVE-2024-0012 (9.3) hands an unauthenticated attacker that admin. Both in CISA KEV since 18 Nov 2024, with known ransomware use. A base score is severity, not patch priority. #CVSS #VulnManagement

    1000057
    48 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Federal agencies are required to remediate by 2024-12-09 or apply mitigations per vendor guidance. CISA KEV CISA added CVE-2024-0012 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-18, confirming active exploitation in the wild.

    Post summary

    CISA confirmed CVE‑2024‑0012 is being exploited in the wild, with advisory deadlines and vendor mitigations for federal agencies.

    1000037
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CISA added CVE-2024-0012 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-18, confirming active exploitation in the wild. CISA KEV PAN-OS management interface auth bypass is now in CISA KEV and linked to ransomware use; patch or pull exposure, and keep…

    Post summary

    CISA added CVE‑2024‑0012 to its KEV list, confirming that the PAN‑OS authentication bypass is actively exploited, with a patch already available.

    1000040
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-0012: PAN-OS management interface auth bypass is now in CISA KEV and linked to ransomware use; patch or pull exposure, and keep management off the internet.

    Post summary

    CVE-2024-0012 is listed in the CISA KEV and tied to ransomware use, indicating active exploitation; a patch is available and management interfaces should be isolated from the internet.

    1000041
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    The weakness aligns with CWE-306 (Missing Authentication for Critical Function), consistent with an auth bypass class flaw. NVD entry MITRE CVE CISA added CVE-2024-0012 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-18, confirming active exploitation in…

    Post summary

    CISA lists CVE-2024-0012 as a known exploited vulnerability, confirming real‑world exploitation, but no proof‑of‑concept or patch details are included.

    1000059
    152 followersView on X
  • Alex Wingfield@AlexWingfield_
    Active Exploitation

    2/ The fun part, CVE-2024-0012 scored 9.3, its buddy 9474 scored 6.9, so one got queued for maintenance, the other ignored. Chained, they handed out root on 13,000 devices like conference swag.

    Post summary

    The post reports that CVE‑2024‑0012, leveraged with CVE‑9474, was actively exploited in the wild, compromising approximately 13,000 devices by elevating privileges.

    1000047
    80 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @RoryCrave CVE-2024-0012 and CVE-2024-9474 are PAN-OS flaws that resulted in over 2,000 firewalls being compromised in November 2024, with attackers gaining root privileges via active exploitation. #InfoSec 🛡️

    Post summary

    This tweet claims that CVE-2024-0012 and CVE-2024-9474 were actively exploited, compromising over 2,000 PAN‑OS firewalls and granting attackers root privileges.

    1000045
    319 followersView on X
  • Rory J Bernier@RoryCrave
    Active Exploitation

    🚨 Palo Alto Networks has reported ~500 vulnerabilities to date The pattern is concerning: • CVE-2024-3400: Zero-day exploited BEFORE patches • 2,000+ firewalls compromised via CVE-2024-0012/9474 • CVE-2025-0108: Exploited within 24 HOURS of disclosure Even "enterprise-grade" security has gaps. Defense in depth isn't optional. #CyberSecurity #InfoSec #ZeroDay

    Post summary

    The tweet reports that Palo Alto Networks has identified roughly 500 vulnerabilities, with several (e.g., CVE-2024‑3400, CVE-2024‑0012/9474, CVE‑2025‑0108) being actively exploited in the wild before patches were available.

    10000191
    3.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers chained CVE-2024-0012 and CVE-2024-9474 to gain root access on PAN-OS devices, bypassing authentication entirely before escalating privileges. With ~2,000 compromised firewalls, they moved laterally through networks and established persistent C2 channels. Runtime segmentation helps contain such post-compromise activity. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/operation-lunar-peek-cve-2024-0012-cve-2024-9474

    Post summary

    Attackers exploited CVE-2024-0012 and CVE-2024-9474 to gain root access on PAN-OS firewalls, compromising around 2,000 devices and establishing persistent C2 channels, demonstrating active exploitation in the wild.

    0000065
    1.9K followersView on X
  • BetterMSSP@bettermssp
    General

    Your clients' #PaloAlto firewalls had admin access wide open for 30 days. You need to know if they got hit before they do. Audit logs today or own the breach conversation tomorrow. #mssp #zeroday #hackers #CVE-2024-0012 https://t.co/OW7njtZhv3

    Post summary

    The tweet warns that PaloAlto firewalls had open admin access for 30 days (CVE‑2024‑0012) and urges admins to audit logs for possible breaches, but offers no technical or exploit details.

    0000082
    16 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-0012-pan-os #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link suggests that CVE-2024-0012 on PAN OS is being actively exploited, but the brief text does not provide additional details or supporting code.

    0000033
    152 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: Palo Alto Networks PAN-OS flaws CVE-2024-0012 and CVE-2024-9474 actively exploited, enable unauth to admin then root on firewalls, patch to 11.2.4-h1, 11.1.5-h1, 11.0.6-h1, 10.2.12-h2 now. https://threatcluster.io/cluster/critical-vulnerabilities-disclosed-in-palo-alto-networks-pan-45158ba9

    Post summary

    Two PAN‑OS CVEs (CVE‑2024‑0012, CVE‑2024‑9474) are being actively exploited to obtain unauthenticated admin then root access on firewalls; vendor patches for multiple releases are now available.

    0000065
    160 followersView on X
CPE platform detail117 entries

117 of 117 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.1--
OSpaloaltonetworkspan-os10.2.1--
OSpaloaltonetworkspan-os10.2.1--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.12--
OSpaloaltonetworkspan-os10.2.12--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.6--
OSpaloaltonetworkspan-os10.2.6--
OSpaloaltonetworkspan-os10.2.6--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.4--
OSpaloaltonetworkspan-os11.0.4--
OSpaloaltonetworkspan-os11.0.4--
OSpaloaltonetworkspan-os11.0.4--
OSpaloaltonetworkspan-os11.0.5--
OSpaloaltonetworkspan-os11.0.5--
OSpaloaltonetworkspan-os11.0.6--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.1--
OSpaloaltonetworkspan-os11.1.1--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.5--
OSpaloaltonetworkspan-os11.2.0--
OSpaloaltonetworkspan-os11.2.1--
OSpaloaltonetworkspan-os11.2.2--
OSpaloaltonetworkspan-os11.2.2--
OSpaloaltonetworkspan-os11.2.3--
OSpaloaltonetworkspan-os11.2.4--

Explore more