PAN-OS

Palo Alto Networks · current 12.2.3

Are you Palo Alto Networks? Claim this page

The current version of PAN-OS is 12.2.3 (as of 27/08/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2020-2021Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityRansomware

    10.0 critical · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityRansomware

    10.0 critical · over the network, without login · CISA deadline was 19 Apr 24

  • CVE-2024-0012Palo Alto Networks PAN-OS Management Interface Authentication Bypass VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 9 Dec 24

  • CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityRansomware

    9.1 critical · over the network, without login · CISA deadline was 1 Jun

  • CVE-2019-1579Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityRansomware

    8.1 high · over the network, without login · CISA deadline was 10 Jul 22

  • CVE-2024-9474Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityRansomware

    7.2 high · over the network, with admin rights only · CISA deadline was 9 Dec 24

  • CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 8 Sept 22

  • CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 9 May

  • CVE-2025-0108Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    9.1 critical · over the network, without login · CISA deadline was 11 Mar 25

  • CVE-2022-0028Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

    8.6 high · over the network, without login · CISA deadline was 12 Sept 22

  • CVE-2024-3393Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

    7.5 high · over the network, without login · CISA deadline was 20 Jan 25

  • CVE-2025-0111Palo Alto Networks PAN-OS File Read Vulnerability

    6.5 medium · over the network, with a basic account · CISA deadline was 13 Mar 25

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

PAN-OS at a glance

PAN-OS is the operating system on Palo Alto Networks firewalls, a mainstay in larger enterprises. Palo Alto ships PAN-OS releases plus security advisories; as a perimeter platform — and one that has seen actively exploited vulnerabilities — prompt patching is essential.

For admins the right combination of PAN-OS version and content updates matters, along with management/firewall (Panorama) compatibility. Never expose the management interface to the internet, apply advisories on a priority basis, and take a config snapshot before upgrading. On HA pairs follow the documented order, and read the known issues. After upgrading, verify VPN and critical policies. Track the PAN-OS version and its support lifecycle per platform; subscribe to Palo Alto's security advisories.

Support cycles (endoflife.date)

CycleLatest versionStatus
12.212.2.3EOL 30 Jul 29
12.112.1.10EOL 28 Aug 28
11.211.2.15EOL 2 May 27
11.111.1.16-h2EOL 3 May 27
11.011.0.6-h1End of Life
10.210.2.18-h10End of Life
10.110.1.14-h20End of Life
10.010.0.12-h6End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
12.2.3STABLE27/08/2026Release notes →
12.2.2STABLE30/07/2026Release notes →
12.1.8STABLE07/07/2026Release notes →
12.1.7-h1STABLE22/06/2026Release notes →

Frequently asked questions

What is the latest version of PAN-OS?
PAN-OS 12.2.3, released 27/08/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the PAN-OS release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new PAN-OS updates?
Tick PAN-OS off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new PAN-OS version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current PAN-OS version and keeps it up to date. Anyone may embed it, no account needed.

PAN-OS badge
[![PAN-OS](https://patchletter.com/badge/pan-os.svg)](https://patchletter.com/en/software/pan-os)
https://patchletter.com/badge/pan-os.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Firewalls & Security