A critical command injection flaw in Palo Alto Networks GlobalProtect exposed internet-facing devices running affected PAN-OS versions to unauthenticated remote code execution with root-level access. Palo Alto confirmed the vulnerability was being exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog. The issue affected systems with GlobalProtect enabled on PAN-OS 10.2, 11.0, and 11.1, and public proof-of-concept exploit code increased the urgency for defenders to patch.
Finland’s National Cyber Security Centre said it issued a serious warning after receiving the first breach notifications tied to the flaw and identified several hundred potentially vulnerable Palo Alto devices in domestic networks. About 15 incident reports related to Palo Alto devices were received, though no more serious breach cases were identified. Early vendor guidance that disabling telemetry could mitigate risk was later deemed insufficient, prompting a shift to immediate patching; fixes were released for supported branches including 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3, after which the Finnish warning was withdrawn as the threat subsided.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Palo Alto disclosed a serious PAN-OS vulnerability affecting firewall management interfaces that allows an unauthenticated attacker to invoke certain PHP scripts and impact system integrity and confidentiality. The vendor released fixes for supported PAN-OS 10.1, 10.2, 11.1, and 11.2 versions, while noting exploitation attempts and public proof-of-concept code.
The Finnish National Cyber Security Centre removed its earlier warning because the threat to organizations had subsided after affected devices were updated. This marked the de-escalation of the domestic response to the vulnerability.
During the response period, Finland’s National Cyber Security Centre received around 15 incident reports related to Palo Alto devices, though no more serious breach cases were identified. The reports reflected active domestic impact from the vulnerability.
Finland’s National Cyber Security Centre issued a serious warning about the Palo Alto GlobalProtect vulnerability after receiving the first incident notifications in Finland. The centre observed several hundred potentially vulnerable devices in domestic networks.
By 17 April 2024, Palo Alto had identified fixed releases including PAN-OS 10.2.9-h1, 11.0.4-h1, 11.1.2-h3, and later versions, with additional fixes for older maintenance branches. A Threat Prevention mitigation and support workflows for compromise checks remained available.
By 17 April 2024, it became clear that earlier guidance to disable telemetry was not sufficient protection, especially after proof-of-concept exploit code became public. Defenders were urged to install vendor patches immediately, and CISA had added the issue to its Known Exploited Vulnerabilities catalog.
Palo Alto Networks published initial patches for a critical command injection vulnerability affecting GlobalProtect on PAN-OS 10.2, 11.0, and 11.1. The flaw could allow an unauthenticated remote attacker to gain root access and execute arbitrary code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.