Home Palo Alto Networks CVE-2025-0108
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to Palo Alto Networks

CVE-2025-0108

Exploited

PAN-OS - Management Web Interface

Palo Alto Networks CVSS 9.1 Updated March 16, 2026

Executive Risk Summary

"An authentication bypass vulnerability in the Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to the management web interface to bypass authentication and invoke certain PHP scripts, potentially impacting integrity and confidentiality. This issue can be mitigated by restricting access to the management web interface to trusted internal IP addresses."

Operational Audit Arsenal

Target Type Firmware Image
Target Asset PAN-OS
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Palo Alto Networks). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Moderate

Internal Work Notes

PAN-OS authentication bypass vulnerability (CVE-2025-0108) - restrict management web interface access to trusted IP addresses and apply recommended patches

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Palo Alto Networks Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.