CVE-2024-3400: Palo Alto Networks PAN-OS Command Injection Vulnerability.
Palo Alto Networks PAN-OS Command Injection Vulnerability. Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
- CISA KEV-listed (remediation due 2024-04-19)
- used in ransomware campaigns
- EPSS 100.0% (100.0% percentile)
- CVSS 10 critical
Detection rules
- Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - File Creation medium
- Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection high
- Python Path Configuration File Creation - Linux medium
- Python Path Configuration File Creation - MacOS medium
- Python Path Configuration File Creation - Windows medium
Exploiting malware & tools
Related briefings
- Hackers disable Windows Defender and dump credentials after a ColdFusion break-in 2026-06-30
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants 2026-02-16