Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA confirmed CVE‑2024‑0012 is being exploited in the wild, with advisory deadlines and vendor mitigations for federal agencies.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA added CVE‑2024‑0012 to its KEV list, confirming that the PAN‑OS authentication bypass is actively exploited, with a patch already available.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CVE-2024-0012 is listed in the CISA KEV and tied to ransomware use, indicating active exploitation; a patch is available and management interfaces should be isolated from the internet.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA lists CVE-2024-0012 as a known exploited vulnerability, confirming real‑world exploitation, but no proof‑of‑concept or patch details are included.
Alex Wingfield[verified]@AlexWingfield_Active Exploitation
The post reports that CVE‑2024‑0012, leveraged with CVE‑9474, was actively exploited in the wild, compromising approximately 13,000 devices by elevating privileges.
transilienceai[verified]@transilienceaiActive Exploitation
This tweet claims that CVE-2024-0012 and CVE-2024-9474 were actively exploited, compromising over 2,000 PAN‑OS firewalls and granting attackers root privileges.
Rory J Bernier[verified]@RoryCraveActive Exploitation
The tweet reports that Palo Alto Networks has identified roughly 500 vulnerabilities, with several (e.g., CVE-2024‑3400, CVE-2024‑0012/9474, CVE‑2025‑0108) being actively exploited in the wild before patches were available.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
Attackers exploited CVE-2024-0012 and CVE-2024-9474 to gain root access on PAN-OS firewalls, compromising around 2,000 devices and establishing persistent C2 channels, demonstrating active exploitation in the wild.