PAN-OS GlobalProtect command injection
Remote-access gateways sit at a particularly sensitive boundary: they accept untrusted internet traffic and often hold privileged network position. This record reinforces a simple incident discipline—maintain a precise edge-device inventory, make owner and…
- Original severity
- critical; CVSS 9.8 source-reported; not rescored by vulns.co
- Public source
- github advisory
- Program / vendor
- Palo Alto Networks
- Product / surface
- PAN-OS GlobalProtect gateway feature
- Weakness
- Command injection · CWE-20, CWE-77
- Affected boundary
- network gateway input-to-command boundary
- Disclosure date
- 2024-04-12
- Public status checked
- 2026-09-10
What the evidence established
The advisory identifies untrusted input reaching command-processing behavior in an exposed remote-access product feature.
Why the impact was credible
The source rates the issue Critical with CVSS 9.8; externally reachable edge systems magnify remediation urgency.
Durable engineering lesson
Remote-access gateways sit at a particularly sensitive boundary: they accept untrusted internet traffic and often hold privileged network position. This record reinforces a simple incident discipline—maintain a precise edge-device inventory, make owner and version visible, and test remediation from the perspective of actual exposed services rather than configuration intent.
Control pattern
Apply the vendor remediation, restrict management and remote-access exposure, and verify compensating controls only as temporary measures.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-10.