Palo Alto Networks disclosed and patched CVE-2024-3400, a critical CVSS 10.0 flaw in PAN-OS that allows unauthenticated attackers to achieve remote code execution through an arbitrary file creation issue leading to OS command injection. The vulnerability affects PAN-OS 10.2, 11.0, and 11.1 when GlobalProtect Gateway or Portal is enabled, while Cloud NGFW, Panorama appliances, and Prisma Access are not affected. Volexity reported active in-the-wild exploitation, prompting Palo Alto to release hotfixes and Threat Prevention signatures 95187, 95189, and 95191 and to urge immediate upgrades.
Post-compromise activity tracked by Unit 42 as Operation MidnightEclipse showed attackers gaining root-level execution on exposed firewalls, attempting limited data exfiltration, and establishing persistence. Researchers said the actor tried to deploy a custom Python backdoor called UPSTYLE and, when that failed, installed a cron-job backdoor instead. Updated guidance also clarified that disabling device telemetry is not an effective mitigation, and defenders were advised to patch immediately, enable threat prevention protections, and hunt for published indicators of compromise including malicious IPs, domains, URLs, and file hashes.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published a notice warning that CVE-2024-3400 was critically severe and actively exploited in the wild, and urged organizations to patch immediately. The alert also highlighted that newer information showed telemetry did not need to be enabled for exploitation and shared hunting guidance and indicators of compromise.
MBSD-SOC reported first detecting attacks targeting CVE-2024-3400 on 2024-04-17 and observed detections rise sharply from 2024-04-21 through 2024-04-25. The activity included file-creation attempts via /ssl-vpn/hipreport.esp and command-injection attempts using curl or wget to fetch and execute external payloads.
Palo Alto Networks Unit 42 reported that exploitation tied to CVE-2024-3400 involved limited exfiltration, interactive command execution, and persistence attempts under the name Operation MidnightEclipse. The actor attempted to deploy a custom Python backdoor called UPSTYLE and, after failing, installed a cron job backdoor instead.
Palo Alto Networks released hotfixes and Threat Prevention signatures 95187, 95189, and 95191 to mitigate CVE-2024-3400. Guidance also advised customers to upgrade to patched versions and use protection profiles if immediate patching was not possible.
Palo Alto Networks publicly disclosed CVE-2024-3400 as an arbitrary file creation vulnerability leading to OS command injection in PAN-OS GlobalProtect. The advisory stated the flaw affected PAN-OS 10.2, 11.0, and 11.1 when GlobalProtect gateway or portal was enabled.
Volexity identified active exploitation of a zero-day unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS GlobalProtect, later tracked as CVE-2024-3400. The discovery established that affected internet-facing firewalls were being targeted before public disclosure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcecsirt.sk
Open sourcevolexity.com
Open sourcesecurity.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.