Palo Alto Networks says it has repaired two major firewall zero-days used in thousands of attacks


  • Palo Alto Networks releases patch for two serious bugs affecting its firewalls
  • The flaws were exploited in the wild to drop malware
  • CISA has added them to the KEV catalogue

Palo Alto Networks has revealed that it has fixed two major vulnerabilities in its firewalls.

The bugs are an authentication bypass in the PAN-OS management web interface (CVE-2024-0012) and a privilege escalation error in PAN-OS (CVE-2024-9474). The former has a severity score of 9.3 (critical) and allows criminals to gain administrative privileges on the target endpoint, and the latter has a lower score, 6.9 (medium), but helps execute commands on the firewall .