Recently patched PAN OS firewall bug actively exploited in the wild

Recently patched PAN OS firewall bug actively exploited in the wild

Palo Alto Networks has confirmed that a recently patched critical vulnerability in its PAN-OS firewall, tracked as CVE-2025-0108, is being actively exploited by threat actors. The vulnerability, which was disclosed on February 12, allows unauthenticated attackers to bypass authentication mechanisms, granting them access to the firewall’s management interface.

“Palo Alto Networks has observed exploit attempts chaining CVE-2025-0108 with CVE-2024-9474 and CVE-2025-0111 on unpatched and unsecured PAN-OS web management interfaces,” the company noted in an updated advisory.

Security researchers at the threat intelligence firm GreyNoise reported the first observed exploitation attempts on February 13. While the exact nature of the exploitation remains unclear, GreyNoise has classified the activity as “malicious.” By Tuesday, February 18, GreyNoise had detected exploit attempts originating from nearly 30 unique IP addresses.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-0108 and another flaw impacting SonicWall SonicOS SSLVPN (CVE-2024-53704) to its Known Exploited Vulnerabilities (KEV) catalog.

Back to the list

Latest Posts

UNC6148 threat actor actively targets outdated and patched SonicWall devices

UNC6148 threat actor actively targets outdated and patched SonicWall devices

The group is using stolen credentials and OTP seeds to regain access to devices even after security updates have been applied.
17 July 2025
Google patches Chrome zero-day allowing sandbox escape

Google patches Chrome zero-day allowing sandbox escape

The flaw stems from insufficient validation of untrusted input in ANGLE and GPU.
16 July 2025
Ukrainian police dismantle major server network used for malware distribution

Ukrainian police dismantle major server network used for malware distribution

Authorities identified a 33-year-old French national as the organizer of the illegal operation.
16 July 2025