# Palo Alto Networks vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 7 Palo Alto Networks CVEs, 6 in the CISA Known Exploited Vulnerabilities catalog, 5 used in ransomware campaigns, linked to 17 tracked threat campaigns and 9 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 7 Palo Alto Networks CVEs published between 2016-11-15 and 2026-09-15. The busiest month was 2026-05 (2 new CVEs). 6 of them (86%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 7 of 7 tracked Palo Alto Networks CVEs.

- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400) — CRITICAL 10 · KEV · Ransomware · EPSS 100% · 2024-04-12
- [CVE-2024-0012](https://intel.threadlinqs.com/cve/CVE-2024-0012) — CRITICAL 9.8 · KEV · Ransomware · EPSS 99.7% · 2024-11-18
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — HIGH 7 · KEV · Ransomware · EPSS 93.9% · 2016-11-10
- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393) — HIGH 7.5 · KEV · EPSS 77.7% · 2024-12-27
- [CVE-2026-0300](https://intel.threadlinqs.com/cve/CVE-2026-0300) — CRITICAL 9.8 · KEV · Ransomware · EPSS 4.5% · 2026-05-06
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257) — CRITICAL 9.1 · KEV · Ransomware · EPSS 0.1% · 2026-05-13
- [CVE-2026-0310](https://intel.threadlinqs.com/cve/CVE-2026-0310) — HIGH 7.2 · EPSS 0.3% · 2026-09-10

## Products affected

Threadlinqs normalises CPE and CNA product records across all 7 CVEs; 12 distinct Palo Alto Networks products are affected. The most frequently affected:

- Pan-os — 7 CVEs
- Prisma Access — 5 CVEs
- Cloud NGFW — 3 CVEs
- Pa-1410 — 1 CVE
- Pa-1420 — 1 CVE
- Pa-3410 — 1 CVE
- Pa-3420 — 1 CVE
- Pa-3430 — 1 CVE
- Pa-3440 — 1 CVE
- Pa-410 — 1 CVE
- Pa-410R — 1 CVE
- Pa-410R-5G — 1 CVE

## Threat activity

17 tracked threat campaigns reference Palo Alto Networks products or exploit Palo Alto Networks CVEs:

- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)](https://intel.threadlinqs.com/threat/TL-2026-2649) — HIGH — 2026-09-25
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — HIGH — 2026-09-19
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE](https://intel.threadlinqs.com/threat/TL-2026-2440) — CRITICAL — 2026-09-10
- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2](https://intel.threadlinqs.com/threat/TL-2026-2368) — HIGH — 2026-09-07
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH — 2026-08-26
- [JA4H Fingerprinting Detects Sliver C2 Deployed via Chained PAN-OS CVE-2024-0012/CVE-2024-9474 Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2144) — HIGH — 2026-08-25
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH — 2026-08-23
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — MEDIUM — 2026-07-29
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — 2026-07-02
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2](https://intel.threadlinqs.com/threat/TL-2026-1088) — HIGH — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — 2026-07-01
- [Palo Alto Networks PAN-OS / Prisma Access GlobalProtect Authentication Bypass (CVE-2026-0257) — Active Exploitation, CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0631) — CRITICAL — 2026-05-29
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking)](https://intel.threadlinqs.com/threat/TL-2026-0498) — CRITICAL — 2026-05-12
- [PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series Firewalls](https://intel.threadlinqs.com/threat/TL-2026-0465) — CRITICAL — 2026-05-06
- [CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter Security Collapse](https://intel.threadlinqs.com/threat/TL-2026-0112) — HIGH — 2026-02-16
- [Coordinated Scanning Campaign Against Fortinet SSL VPN and Palo Alto GlobalProtect Infrastructure Detected via GreyNoise Vendor CVE / Tag Spike Signals](https://intel.threadlinqs.com/threat/TL-2026-1469) — MEDIUM — 2026-01-25

## Threat actors targeting Palo Alto Networks

Named threat actors attributed to campaigns that involve Palo Alto Networks products or CVEs, with the number of linked campaigns:

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1 campaign
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1 campaign
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1 campaign
- [Play - G1040](https://intel.threadlinqs.com/actor/Play%20-%20G1040) — 1 campaign
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1 campaign
- [Sinobi](https://intel.threadlinqs.com/actor/Sinobi) — 1 campaign
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1 campaign

## How to prioritise Palo Alto Networks patching

This order follows the data Threadlinqs holds for Palo Alto Networks, not a generic severity checklist:

- 6 of 7 Palo Alto Networks CVEs (86%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400), [CVE-2024-0012](https://intel.threadlinqs.com/cve/CVE-2024-0012), [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195).
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-0310](https://intel.threadlinqs.com/cve/CVE-2026-0310) (0.3%).
- 4 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 8.6); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/palo-alto-networks
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
