PAN-OS

Palo Alto Networks · current 12.2.2

The current version of PAN-OS is 12.2.2 (as of 30/07/2026). patchletter checks the official source daily and emails you every new release.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.

  • CVE-2020-2021Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityRansomware

    10.0 critical · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityRansomware

    10.0 critical · over the network, without login · CISA deadline was 19 Apr 24

  • CVE-2024-0012Palo Alto Networks PAN-OS Management Interface Authentication Bypass VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 9 Dec 24

  • CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityRansomware

    9.1 critical · over the network, without login · CISA deadline was 1 Jun

  • CVE-2019-1579Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityRansomware

    8.1 high · over the network, without login · CISA deadline was 10 Jul 22

  • CVE-2024-9474Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityRansomware

    7.2 high · over the network, with admin rights only · CISA deadline was 9 Dec 24

  • CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 8 Sept 22

  • CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 9 May

  • CVE-2025-0108Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    9.1 critical · over the network, without login · CISA deadline was 11 Mar 25

  • CVE-2022-0028Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

    8.6 high · over the network, without login · CISA deadline was 12 Sept 22

  • CVE-2024-3393Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

    7.5 high · over the network, without login · CISA deadline was 20 Jan 25

  • CVE-2025-0111Palo Alto Networks PAN-OS File Read Vulnerability

    6.5 medium · over the network, with a basic account · CISA deadline was 13 Mar 25

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

PAN-OS at a glance

PAN-OS is the operating system on Palo Alto Networks firewalls, a mainstay in larger enterprises. Palo Alto ships PAN-OS releases plus security advisories; as a perimeter platform — and one that has seen actively exploited vulnerabilities — prompt patching is essential.

For admins the right combination of PAN-OS version and content updates matters, along with management/firewall (Panorama) compatibility. Never expose the management interface to the internet, apply advisories on a priority basis, and take a config snapshot before upgrading. On HA pairs follow the documented order, and read the known issues. After upgrading, verify VPN and critical policies. Track the PAN-OS version and its support lifecycle per platform; subscribe to Palo Alto's security advisories.

Support cycles (endoflife.date)

CycleLatest versionStatus
12.212.2.2EOL 30 Jul 29
12.112.1.9EOL 28 Aug 28
11.211.2.13-h1EOL 2 May 27
11.111.1.16-h1EOL 3 May 27
11.011.0.6-h1End of Life
10.210.2.18-h9End of Life
10.110.1.14-h20End of Life
10.010.0.12-h6End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
12.2.2STABLE30/07/2026Release notes →
12.1.8STABLE07/07/2026Release notes →
12.1.7-h1STABLE22/06/2026Release notes →

Frequently asked questions

What is the latest version of PAN-OS?
PAN-OS 12.2.2, released 30/07/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the PAN-OS release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new PAN-OS updates?
Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.

Never miss a PAN-OS update

We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.

Watch PAN-OS

Embed this badge

Shows the current PAN-OS version and updates itself. Free to use, no account needed.

PAN-OS badge
[![PAN-OS](https://patchletter.com/badge/pan-os.svg)](https://patchletter.com/en/software/pan-os)
https://patchletter.com/badge/pan-os.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Firewalls & Security