CVE-2024-9465General(paloaltonetworks / expedition)

LOWCVSS 9.1 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for paloaltonetworks expedition systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • expedition

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
expedition

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-08: 1Mentions · 2026-08-21: 1Active Exploitation · 2026-08-21: 104-0808-21
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Classification over time
DateTotalLabels
2026-04-081
General1
2026-08-211
Active Exploitation1
Full discourse2 posts
  • Team Cymru Research@teamcymru_S2
    General

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet lists the top 25 CVEs by exploitation attempts but lacks detailed technical info, PoC links, or active exploitation claims, making it a generic mention without deeper insights.

    070921.2K
    5.5K followersView on X
  • Netconverter@Netconverterai
    Active Exploitation

    CISA later added multiple Expedition vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2024-5910, CVE-2024-9463 and CVE-2024-9465. https://t.co/Zn3wjOeHPU

    Post summary

    The post informs that CISA has added CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465 to its Known Exploited Vulnerabilities catalog, confirming that these exploits are active in the wild.

    0000030
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppaloaltonetworksexpedition---

Explore more