Palo Alto Networks disclosed multiple critical and high-severity vulnerabilities in Expedition, its migration and management tool for firewalls, affecting versions earlier than 1.2.96. The flaws include SQL injection, reflected XSS, unauthorized access to sensitive data, arbitrary file read and write, and remote command execution. According to the advisory and follow-on reporting, attackers can use the bugs to obtain firewall credentials, device configurations, and PAN-OS API keys, creating a path from Expedition compromise to broader access across connected firewall environments.
The most serious risk is remote code execution on Expedition and potential full compromise of connected PAN-OS firewalls. Public reporting said a proof of concept is available for CVE-2024-9464 when chained with the older CVE-2024-5910, which can reset administrator accounts and further ease takeover. Palo Alto Networks urged organizations to upgrade to Expedition 1.2.96 or later, rotate credentials and cryptographic material on both Expedition and managed firewalls, and restrict or disable Expedition where immediate patching is not possible.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that a public proof-of-concept exists for CVE-2024-9464 when chained with the older CVE-2024-5910, a combination that can reset administrator accounts. The reported impact includes possible remote code execution on Expedition and potential full compromise of connected PAN-OS firewalls.
Palo Alto Networks released security updates for multiple critical and high-severity Expedition flaws, including issues enabling SQL injection, XSS, unauthorized data access, arbitrary file read/write, and command execution. The vendor recommended upgrading to version 1.2.96 or later and rotating credentials and cryptographic material.
Palo Alto Networks published advisory PAN-SA-2024-0010 covering multiple vulnerabilities in Expedition that can expose firewall credentials and affect versions earlier than 1.2.96.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesecurity.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.