Exploitation timeline
Threadlinqs has recorded 7 Palo Alto Networks CVEs published between and . The busiest month was 2026-05 (2 new CVEs). 6 of them (86%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 7 of 7 tracked Palo Alto Networks CVEs.
- CVE-2024-3400critical 10KEVRansomwareEPSS 100%
- CVE-2024-0012critical 9.8KEVRansomwareEPSS 99.7%
- CVE-2016-5195high 7KEVRansomwareEPSS 93.9%
- CVE-2024-3393high 7.5KEVEPSS 77.7%
- CVE-2026-0300critical 9.8KEVRansomwareEPSS 4.5%
- CVE-2026-0257critical 9.1KEVRansomwareEPSS 0.1%
- CVE-2026-0310high 7.2EPSS 0.3%
Products affected
Threadlinqs normalises CPE and CNA product records across all 7 CVEs; 12 distinct Palo Alto Networks products are affected. The most frequently affected:
- Pan-os 7 CVEs
- Prisma Access 5 CVEs
- Cloud NGFW 3 CVEs
- Pa-1410 1 CVE
- Pa-1420 1 CVE
- Pa-3410 1 CVE
- Pa-3420 1 CVE
- Pa-3430 1 CVE
- Pa-3440 1 CVE
- Pa-410 1 CVE
- Pa-410R 1 CVE
- Pa-410R-5G 1 CVE
Threat activity
17 tracked threat campaigns reference Palo Alto Networks products or exploit Palo Alto Networks CVEs:
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)HIGH
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)HIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCECRITICAL
- Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2HIGH
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- JA4H Fingerprinting Detects Sliver C2 Deployed via Chained PAN-OS CVE-2024-0012/CVE-2024-9474 ExploitationHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware GroupsMEDIUM
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- Palo Alto Networks PAN-OS / Prisma Access GlobalProtect Authentication Bypass (CVE-2026-0257) — Active Exploitation, CISA KEVCRITICAL
- SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking)CRITICAL
- PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series FirewallsCRITICAL
- CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter Security CollapseHIGH
- Coordinated Scanning Campaign Against Fortinet SSL VPN and Palo Alto GlobalProtect Infrastructure Detected via GreyNoise Vendor CVE / Tag Spike SignalsMEDIUM
Threat actors targeting Palo Alto Networks
Named threat actors attributed to campaigns that involve Palo Alto Networks products or CVEs, with the number of linked campaigns:
How to prioritise Palo Alto Networks patching
This order follows the data Threadlinqs holds for Palo Alto Networks, not a generic severity checklist:
- 6 of 7 Palo Alto Networks CVEs (86%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2024-3400, CVE-2024-0012, CVE-2016-5195.
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-0310 (0.3%).
- 4 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 8.6); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.