CVE-2024-9474Active Exploitation(paloaltonetworks / pan-os)

MEDIUMCVSS 7.2 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Peaked 6d ago at 1 mentions (2026-01-28); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Products
pan-os

5 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-01-28: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-24: 1Mentions · 2026-07-09: 1Mentions · 2026-08-10: 1Mentions · 2026-10-06: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-08-10: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-24: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-10: 101-2803-3003-3104-2407-0908-1010-06
Signal classification2 categories
Active Exploitation
466.7%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-281
Active Exploitation1
2026-03-301
General1
2026-03-311
General1
2026-04-241
Active Exploitation1
2026-07-091
Active Exploitation1
2026-08-101
Active Exploitation1
Full discourse7 posts
  • Cyb3rVolt3x@AndraxPentester

    CVE-2024-9474 scores 6.9 Medium under CVSS 4.0. It needs PAN-OS admin first. CVE-2024-0012 (9.3) hands an unauthenticated attacker that admin. Both in CISA KEV since 18 Nov 2024, with known ransomware use. A base score is severity, not patch priority. #CVSS #VulnManagement

    1000055
    48 followersView on X
  • Horizon3.ai@Horizon3ai
    Active Exploitation

    Here's how #NodeZero got there: • Identified an exposed PAN-OS web service • Exploited CVE-2024-9474 for privilege escalation

    Post summary

    The post reports that threat actor #NodeZero exploited CVE-2024-9474, an exposed PAN‑OS web service, to achieve privilege escalation, indicating active exploitation in the wild.

    10000113
    2.9K followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-9474 (EPSS 94.00%) Palo Alto Networks PAN-OS privilege escalation vulnerability allows PAN-OS admin with access to management web interface to execute arbitrary code. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-9474 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post reports that CVE‑2024‑9474 is a high‑risk privilege‑escalation flaw in Palo Alto Networks PAN‑OS, but it offers no evidence of active exploitation, PoCs, or patches.

    1000058
    311 followersView on X
  • Patrick Roland@DeusLogica
    General

    Timestamp: 2026-03-30T11:11:47.241521 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2024-9474 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-9474 (EPSS 94.00%) A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface t Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-9474 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    The post reports a high EPSS score for CVE-2024-9474, describing it as a privilege escalation flaw in Palo Alto Networks PAN-OS likely exploitable, but provides no PoC, exploit code, or patch details.

    1000048
    307 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @RoryCrave CVE-2024-0012 and CVE-2024-9474 are PAN-OS flaws that resulted in over 2,000 firewalls being compromised in November 2024, with attackers gaining root privileges via active exploitation. #InfoSec 🛡️

    Post summary

    The tweet reports that CVE-2024-0012 and CVE-2024-9474 in PAN-OS resulted in more than 2,000 firewalls being compromised in November 2024, with attackers gaining root privileges—an explicit claim of in-the-wild exploitation.

    1000045
    319 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers chained CVE-2024-0012 and CVE-2024-9474 to gain root access on PAN-OS devices, bypassing authentication entirely before escalating privileges. With ~2,000 compromised firewalls, they moved laterally through networks and established persistent C2 channels. Runtime segmentation helps contain such post-compromise activity. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/operation-lunar-peek-cve-2024-0012-cve-2024-9474

    Post summary

    The report confirms attackers actively exploited CVE‑2024‑0012 and CVE‑2024‑9474 on over 2,000 PAN‑OS firewalls, achieving root access and establishing persistent C2 channels.

    0000065
    1.9K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: Palo Alto Networks PAN-OS flaws CVE-2024-0012 and CVE-2024-9474 actively exploited, enable unauth to admin then root on firewalls, patch to 11.2.4-h1, 11.1.5-h1, 11.0.6-h1, 10.2.12-h2 now. https://threatcluster.io/cluster/critical-vulnerabilities-disclosed-in-palo-alto-networks-pan-45158ba9

    Post summary

    CVE-2024-0012 and CVE-2024-9474 are actively exploited to gain unauthenticated administrative and root access on Palo Alto firewalls. Patches are available for multiple PAN‑OS versions.

    0000065
    160 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os---
OSpaloaltonetworkspan-os10.1.14--
OSpaloaltonetworkspan-os10.1.14--
OSpaloaltonetworkspan-os10.1.14--
OSpaloaltonetworkspan-os10.2.12--
OSpaloaltonetworkspan-os10.2.12--
OSpaloaltonetworkspan-os11.0.6--
OSpaloaltonetworkspan-os11.1.5--
OSpaloaltonetworkspan-os11.2.4--

Explore more