Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
- Severity
- High8.1CVSS 3.1, High
- EPSS
- 46%
- Published
- 19 Jul 2019
- Updated
- 12 Aug 2026
Description
Title, description and vendor guidance are quoted from the source records.
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
Weakness: CWE-134
Known exploited
Added to CISA KEV on 10 Jan 2022
Federal remediation due date: 10 Jul 2022
Known use in ransomware campaigns
Required action: Apply updates per vendor instructions.
Exploit prediction
46% probability of exploitation in the next 30 days (percentile 99%).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Patcharo shows this vulnerability for information but does not match versions for this product yet.
- n/a Palo Alto Networks GlobalProtect Portal/Gateway Interface · PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier releases
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010(opens in a new tab)
- https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-GlobalProtect-with-Uber-as-case-study/(opens in a new tab)
- https://security.paloaltonetworks.com/CVE-2019-1579(opens in a new tab)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1579(opens in a new tab)
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC