CVE-2024-3400Active Exploitation(paloaltonetworks / pan-os)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-04-19. Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Weakness type (CWE)
CWE-20CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 13 classified signals
  • Patch or workaround signal is available
  • 39 mentions across 30 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 13 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 14 signals
  • General: 12 classified signals
  • Disclosure: 6 classified signals
  • Peaked 20d ago at 3 mentions (2026-04-15); latest day: 2
  • 39 total mentions across 30 days

Affected systems

Products
pan-os

18 versions affected across 1 product

Deep dive

Activity timeline39 mentions / 30d
01223Mentions · 2026-01-28: 2Mentions · 2026-02-16: 1Mentions · 2026-02-17: 1Mentions · 2026-02-24: 1Mentions · 2026-03-05: 1Mentions · 2026-03-12: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 2Mentions · 2026-03-31: 1Mentions · 2026-04-15: 3Mentions · 2026-04-21: 1Mentions · 2026-04-25: 1Mentions · 2026-04-29: 3Mentions · 2026-05-01: 1Mentions · 2026-05-03: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-06-04: 1Mentions · 2026-06-07: 1Mentions · 2026-06-12: 1Mentions · 2026-09-10: 1Mentions · 2026-09-16: 1Mentions · 2026-09-20: 1Mentions · 2026-09-21: 1Mentions · 2026-09-22: 1Mentions · 2026-09-23: 2Mentions · 2026-09-24: 1Mentions · 2026-09-27: 2Mentions · 2026-10-05: 1Mentions · 2026-10-06: 2Active Exploitation · 2026-01-28: 2Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-24: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-04-15: 3Active Exploitation · 2026-05-03: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-06-04: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-29: 2Technical Details · 2026-05-03: 1Technical Details · 2026-05-07: 1Technical Details · 2026-09-10: 1Technical Details · 2026-09-22: 101-2802-2403-2004-1504-2905-0606-0709-1609-2209-2710-06
Signal classification4 categories
Active Exploitation
1338.2%
General
1235.3%
Disclosure
617.6%
Patch
38.8%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-282
Active Exploitation2
2026-02-161
Active Exploitation1
2026-02-171
Patch1
2026-02-241
Active Exploitation1
2026-03-051
Active Exploitation1
2026-03-121
General1
2026-03-201
General1
2026-03-232
Active Exploitation1General1
2026-03-311
Patch1
2026-04-153
Active Exploitation3
2026-04-211
Disclosure1
2026-04-251
General1
2026-04-293
Disclosure2General1
2026-05-011
General1
2026-05-031
Active Exploitation1
2026-05-061
Active Exploitation1
2026-05-071
Active Exploitation1
2026-06-041
Active Exploitation1
2026-06-071
General1
2026-06-121
Patch1
2026-09-101
Disclosure1
2026-09-161
General1
2026-09-201
General1
2026-09-211
Disclosure1
2026-09-221
Disclosure1
2026-09-232
General2
2026-09-241
General1
Full discourse20 posts
  • 中島佑允(YusukeNakajima)@nakajimeeee
    General

    もちろん各企業ごとにカスタマイズは必要かもしれないけど、こういうツールを使ってトリアージするのはとてもよさそう。 --- The problem: Triaging a single CVE means querying NVD for CVSS scores, EPSS for exploitation probability, CISA KEV for active exploitation status, GitHub for patches, and VirusTotal for malware associations — then mentally correlating everything. For 50 CVEs, that's an entire day lost. The solution: CVE MCP Server gives Claude direct access to 27 security tools across 21 APIs. Ask "Should we patch CVE-2024-3400?" and Claude queries every relevant source in parallel, calculates a composite risk score, and delivers a prioritized recommendation with evidence. --- https://github.com/mukul975/cve-mcp-server

    Post summary

    The passage describes a triage tool that aggregates vulnerability data from multiple APIs but does not provide proof of concept, exploit details, active exploitation claims, patches, technical vulnerability specifics, or any debunking statements.

    010114804
    2.9K followersView on X
  • Justin Elze@HackingLZ
    General

    @IceSolst PAN has not been without major issues CVE-2024-3400

    Post summary

    The tweet merely references CVE-2024-3400 without providing details, proof of concept, mitigation, or evidence of exploitation, making it an ambiguous, general mention.

    1001402.6K
    69.0K followersView on X
  • Amal Roy@RoyAmal
    General

    Everyone is building AI agents. Very few are giving them real security intelligence. That's the gap. CVE MCP Server gives Claude access to 27 security tools across 21 APIs for vulnerability analysis, threat intelligence, EPSS scoring, CISA KEV lookups, MITRE ATT&CK mapping, Shodan, VirusTotal, and more—all through natural language. Think about what this means. Instead of spending hours jumping between: • NVD databases • CVE feeds • EPSS scores • Shodan searches • Threat intelligence platforms • MITRE ATT&CK references You can simply ask: "Should we patch CVE-2024-3400?" And get a risk-based answer backed by multiple intelligence sources. The interesting part? This isn't another security dashboard. It's a security analyst API for AI agents. We're entering a world where: AI can write code. AI can deploy code. AI can monitor systems. The missing piece is helping AI understand risk. Because every AI-powered company is becoming a software company. And every software company eventually becomes a security company. The biggest opportunity in AI security isn't building smarter firewalls. It's giving AI access to better intelligence. Models create answers. Intelligence creates decisions. And in cybersecurity, decisions are everything.

    Post summary

    The text highlights an AI platform that can query security APIs to answer whether a CVE should be patched, but it contains no exploit details, patch info, or technical specifics.

    4001097
    272 followersView on X
  • nksistemas@nksistemas
    Patch

    Alerta Crítica: CVE-2024-3400 y la Urgencia de Parchear PAN-OS de Palo Alto Networks https://nksistemas.com/alerta-critica-cve-2024-3400-y-la-urgencia-de-parchear-pan-os-de-palo-alto-networks/

    Post summary

    The article alerts about CVE‑2024‑3400 and emphasizes the urgency of applying the PAN‑OS patch from Palo Alto Networks.

    0201092
    6.2K followersView on X
  • ro0TCr4k@ro0TCr4k

    CVE-2024-3400 is the fire drill of the week. Active exploitation of Palo Alto GlobalProtect demands immediate patching. We're seeing weaponized payloads in the wild. Patch now.

    0002076
    508 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    GET /api/v1/cve/CVE-2024-3400 returns CVSS, affected vendors, and known exploit references in one call. No key juggling, no separate lookups. Metered per request. https://www.valtersit.com/cve/pricing/ #ValtersIT #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #docker

    Post summary

    The tweet announces a ValtersIT API endpoint that returns CVSS, affected vendors, and exploit references for CVE-2024-3400 in a single request, without providing PoC, exploit code, active exploitation evidence, or patch details.

    0101063
    1.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Black Shrantac ransomware group weaponizes legitimate admin tools and CVE-2024-3400 for stealth attacks across industrial sectors. Active since September 2025, combining LOTL tactics with double extortion to evade detection. Technical breakdown: • Initial access via CVE-2024-3400 (CVSS 10.0) in EOL Palo Alto PAN-OS 11.0.0 devices, plants trojanized GlobalProtect MSI in firewall update portal • Persistence through SimpleHelp remote access service, Net Monitor for Employees Agent, and new AD domain accounts with elevated privileges • Credential harvesting using native klist[.]exe for Kerberos ticket enumeration and pass-the-ticket attacks (T1558.003) • Lateral movement via RDP, PSExec, MightyViewer VNC, and SSHFS-Win mounted drives - all legitimate tools mimicking admin activity • Defense evasion by disabling Defender via PowerShell, using vendor uninstall utilities, clearing event logs, renaming encryptor binaries Hunt for scheduled tasks created by non-SYSTEM accounts pointing to user directories, and monitor Event ID 4769/4624 for Kerberos anomalies across multiple hosts. #DFIR_Radar

    Post summary

    Black Shrantac is actively exploiting CVE‑2024‑3400, combining it with legitimate admin tools to conduct stealthy, double‑extortion attacks across industrial sectors. The text confirms in‑the‑wild activity and detailed technical exploitation tactics but does not discuss patches or PoCs.

    10010175
    1.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-3400. CVE-2024-3400: Palo Alto GlobalProtect Perfect-10 Command Injection

    Post summary

    The text announces CVE-2024-3400 and identifies it as a command injection vulnerability in Palo Alto GlobalProtect Perfect-10.

    1000034
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Vendor v10.0. CVE-2024-3400 represents a catastrophic vulnerability in Palo Alto Networks' GlobalProtect gateway — the very infrastructure designed to secure network perimete

    Post summary

    CVE-2024-3400 is identified as a catastrophic vulnerability in Palo Alto Networks' GlobalProtect gateway, but the text offers no further details about exploitation, patches, or technical specifics.

    1000047
    125 followersView on X
  • 4fqr@foufqr
    Active Exploitation

    black shrantac ransomware active since sept 2025 uses living-off-the-land tactics and cve-2024-3400 for stealth entry. operates tor leak site for double extortion across sectors. https://industrialcyber.co/industrial-cyber-attacks/black-shrantac-exposes-industrial-environments-to-stealth-ransomware-risk-through-lotl-double-extortion-tactics/ #threatresearch #threatintel #cybersec #cybernews

    Post summary

    The text reports that Black Shrantac ransomware has been actively exploiting CVE-2024-3400 for stealth entry, indicating real-world use of the vulnerability.

    0001073
    11 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @RoryCrave CVE-2024-3400 was a zero-day in PAN-OS firewalls exploited before patches were available, leading to widespread compromise. #VulnerabilityAlert ⚠️

    Post summary

    CVE‑2024‑3400 was actively exploited in the wild, compromising PAN‑OS firewalls before patches were released, leading to widespread incidents.

    1000041
    319 followersView on X
  • Rory J Bernier@RoryCrave
    Active Exploitation

    🚨 Palo Alto Networks has reported ~500 vulnerabilities to date The pattern is concerning: • CVE-2024-3400: Zero-day exploited BEFORE patches • 2,000+ firewalls compromised via CVE-2024-0012/9474 • CVE-2025-0108: Exploited within 24 HOURS of disclosure Even "enterprise-grade" security has gaps. Defense in depth isn't optional. #CyberSecurity #InfoSec #ZeroDay

    Post summary

    The post confirms that Palo Alto Networks vulnerabilities are actively exploited, with zero-day attacks occurring before patches and over 2,000 firewalls compromised.

    10000191
    3.0K followersView on X
  • Bhavesh Verma@xbhaveshverma

    CVEs Explainer #2 CVE-2024-3400 (PAN-OS GlobalProtect Command Injection) A perfect 10.0 CVSS score. This critical command injection flaw in Palo Alto Networks' PAN-OS allowed unauthenticated attackers to execute arbitrary commands with root privileges on firewalls with the GlobalProtect gateway enabled. Actively exploited as a zero-day, it enabled attackers to bypass perimeter security entirely, deploy malware, and establish persistent access across enterprise networks.‌

    0000071
    104 followersView on X
  • DailyCVE@dailycve

    🔴 Palo Alto Networks PAN-#OS, Command Injection, #CVE-2024-3400 (Critical) -DC-Oct2026-2727 https://dailycve.com/palo-alto-networks-pan-os-command-injection-cve-2024-3400-critical-dc-oct2026-2727/

    0000044
    239 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters

    One call to /v1/cve/CVE-2024-3400 returns CVSS, affected CPEs, known exploits, and vendor references in a single JSON response. No joins on your side. https://www.valtersit.com/cve/pricing/ #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    0000053
    1.1K followersView on X
  • ro0TCr4k@ro0TCr4k

    The Palo Alto PAN-OS CVE-2024-3400 zero-day is a stark reminder. Critical infrastructure is often the target, and patch lags are the attacker's advantage. RootCrak's assessment teams are already mapping exposure for clients. Are you?

    0000084
    508 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    General

    Scraping NVD works until rate limits, schema drift, and CPE matching eat your week. One curl gets CVE, vendor, and exploit data already normalized: curl http://valtersit.com/api/cve/CVE-2024-3400 Pricing: https://www.valtersit.com/cve/pricing/ #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    Post summary

    The post promotes an API that returns normalized CVE, vendor, and exploit data for CVE-2024-3400, but it lacks clear indicators of PoC availability, exploit tooling, active exploitation, patching, or detailed vulnerability disclosure.

    0000058
    1.1K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    General

    CVE enrichment in your triage pipeline: one GET returns CVSS, affected vendors, and known exploits. No scraping NVD or cross-referencing three tabs at 2am. curl "https://valtersit.com/api/v1/cve/CVE-2024-3400" Pricing: https://www.valtersit.com/cve/pricing/ #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    Post summary

    Promotional text for a CVE lookup API referencing CVE-2024-3400; it lacks PoC, exploit code, patch, active exploitation evidence, or technical details, fitting the General category.

    0000041
    1.1K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    General

    SOC triage: pull CVE, vendor, exploit data in one call. curl "http://valtersit.com/api/cve/CVE-2024-3400?key=YOUR_KEY" Runs in your enrichment pipeline. Pricing: http://valtersit.com/cve/pricing #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    Post summary

    The tweet promotes an API service that can retrieve CVE, vendor, and exploit data for CVE-2024-3400, but does not provide any PoC, exploit code, active exploitation info, patches, or technical vulnerability details.

    0000047
    1.1K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    Scraping NVD works until you need vendor attribution and exploit status linked to the same CVE. One call instead of three pipelines: curl https://valtersit.com/api/cve/CVE-2024-3400 Pricing: https://www.valtersit.com/cve/pricing/ #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    Post summary

    The tweet shares an API endpoint for retrieving consolidated CVE data (including vendor attribution and exploit status) for CVE-2024-3400, tagging it as an XSS vulnerability, without mentioning exploits, patches, or active exploitation.

    0000041
    1.1K followersView on X
CPE platform detail52 entries

52 of 52 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.1--
OSpaloaltonetworkspan-os10.2.1--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.6--
OSpaloaltonetworkspan-os10.2.6--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.0--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.1--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.2--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.3--
OSpaloaltonetworkspan-os11.0.4--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.1--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.2--

Explore more