Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Cloud NGFW — Vulnerabilities & Security Advisories 65

All 65 CVE vulnerabilities found in Cloud NGFW, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregation for Palo Alto Networks Cloud NGFW, categorized by weakness type. It serves as a centralized resource for understanding security gaps associated with this specific cloud-native firewall solution. The collection encompasses a wide range of vulnerability classifications, including buffer overflows, cross-site scripting, and privilege escalation flaws, spanning from the product's initial public release through recent patches. This comprehensive timeline allows users to observe how security postures have evolved alongside feature updates and threat landscape changes. Visitors can efficiently track vendor advisories to stay informed about newly disclosed issues and recommended remediation steps. By examining the aggregated data, users gain deeper insight into common weakness classes, such as those defined in the Common Weakness Enumeration (CWE), and understand their specific impact on cloud infrastructure. The page also enables the lookup of a product’s historical vulnerability record, providing context for current risk assessments and helping teams prioritize remediation efforts based on severity and exploitability. Whether you are a security administrator reviewing patch notes or a developer analyzing code integrity, this resource offers structured access to critical security intelligence. It supports informed decision-making by consolidating disparate vulnerability reports into a coherent view, facilitating proactive defense strategies and compliance verification.

Vendor: Palo Alto Networks

CVE IDTitleCVSSSeverityPublished
CVE-2025-2182 PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK) CWE-312 6.5AIMediumAI2025-08-13
CVE-2025-4229 PAN-OS: Traffic Information Disclosure Vulnerability CWE-497 5.3AIMediumAI2025-06-13
CVE-2025-4230 PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI CWE-78 7.2AIHighAI2025-06-12
CVE-2025-4231 PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface CWE-77 7.2AIHighAI2025-06-12
CVE-2025-0136 PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices CWE-319 7.5AIHighAI2025-05-14
CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management Web Interface CWE-83 7.2AIHighAI2025-05-14
CVE-2025-0133 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal CWE-79 6.1AIMediumAI2025-05-14
CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets CWE-754 7.5AIHighAI2025-05-14
CVE-2025-0123 PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures CWE-312 4.9AIMediumAI2025-04-11
CVE-2025-0128 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet CWE-754 7.5AIHighAI2025-04-11
CVE-2025-0127 PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series CWE-78 7.2AIHighAI2025-04-11
CVE-2025-0126 PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login CWE-384 8.8AIHighAI2025-04-11
CVE-2025-0125 PAN-OS: Improper Neutralization of Input in the Management Web Interface CWE-83 7.2AIHighAI2025-04-11
CVE-2025-0124 PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface CWE-73 7.1AIHighAI2025-04-11
CVE-2025-0111 PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface CWE-73 6.5 -2025-02-12
CVE-2025-0109 PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface CWE-73 9.1 -2025-02-12
CVE-2025-0108 PAN-OS: Authentication Bypass in the Management Web Interface CWE-306 9.8 -2025-02-12
CVE-2025-0107 Expedition: OS Command Injection Vulnerability CWE-78 10.0 -2025-01-11
CVE-2025-0106 Expedition: Wildcard Expansion Vulnerability CWE-155 5.8 -2025-01-11
CVE-2025-0105 Expedition: Arbitrary File Deletion Vulnerability CWE-73 10.0 -2025-01-11
CVE-2025-0104 Expedition: Cross-Site Scripting (XSS) Vulnerability CWE-79 6.1 -2025-01-11
CVE-2025-0103 Expedition: SQL Injection Vulnerability CWE-89 8.1 -2025-01-11
CVE-2024-3393 PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet CWE-754 7.5 -2024-12-27
CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface CWE-78 5.9 Medium2024-11-18
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) CWE-306 5.9 Medium2024-11-18
CVE-2024-2550 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet CWE-476 7.5AIHighAI2024-11-14
CVE-2024-5920 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator CWE-79 4.8AIMediumAI2024-11-14
CVE-2024-5917 PAN-OS: Server-Side Request Forgery in WildFire CWE-918 5.3AIMediumAI2024-11-14
CVE-2024-2552 PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI) CWE-22 6.5AIMediumAI2024-11-14
CVE-2024-5918 PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User CWE-295 8.1AIHighAI2024-11-14

All 65 known CVE vulnerabilities affecting Cloud NGFW with full Chinese analysis, references, and POCs where available.