Palo Alto Networks disclosed CVE-2025-0108, an authentication bypass flaw in the PAN-OS management web interface, and related reporting shows attackers quickly began probing and exploiting exposed systems. MBSD-SOC said it observed attack attempts starting on 2025-02-14, just two days after public disclosure, and linked the activity to exploitation of both CVE-2025-0108 and the management interface file-read issue CVE-2025-0111. The attacks targeted PAN-OS versions across the 11.1, 10.2, and 10.1/11.2 branches, with public proof-of-concept code already available.
Observed attack traffic was led by sources in France, with additional activity from the United States, Japan, Russia, and Germany during February and March 2025. MBSD-SOC published an example HTTP request used to attempt authentication bypass against the web management interface and urged organizations to update affected firewalls immediately to the latest fixed PAN-OS releases, as internet-facing management interfaces remain a high-value target for opportunistic exploitation.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported increased attack activity during March 2025 against the PAN-OS management interface vulnerabilities CVE-2025-0108 and CVE-2025-0111. The observed traffic primarily originated from France, with additional activity from Japan, the United States, Russia, and Germany.
MBSD-SOC observed attacks targeting CVE-2025-0108 and CVE-2025-0111 starting on February 14, including requests attempting to bypass authentication on the PAN-OS management interface. The report also notes that proof-of-concept code had already been published.
MBSD-SOC reported that CVE-2025-0111, a file read vulnerability in the PAN-OS management web interface, was publicly disclosed. The report ties its disclosure to the same date as CVE-2025-0108.
Palo Alto Networks publicly disclosed CVE-2025-0108, an authentication bypass vulnerability affecting the PAN-OS management web interface. The MBSD-SOC report states this disclosure occurred on the same day as CVE-2025-0111.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.