The current version of PAN-OS is 12.2.3 (as of 27/08/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
10.0 critical · over the network, without login · CISA deadline was 15 Apr 22
10.0 critical · over the network, without login · CISA deadline was 19 Apr 24
- CVE-2024-0012Palo Alto Networks PAN-OS Management Interface Authentication Bypass VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 9 Dec 24
9.1 critical · over the network, without login · CISA deadline was 1 Jun
8.1 high · over the network, without login · CISA deadline was 10 Jul 22
- CVE-2024-9474Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityRansomware
7.2 high · over the network, with admin rights only · CISA deadline was 9 Dec 24
- CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 8 Sept 22
- CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
9.8 critical · over the network, without login · CISA deadline was 9 May
- CVE-2025-0108Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
9.1 critical · over the network, without login · CISA deadline was 11 Mar 25
- CVE-2022-0028Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability
8.6 high · over the network, without login · CISA deadline was 12 Sept 22
- CVE-2024-3393Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
7.5 high · over the network, without login · CISA deadline was 20 Jan 25
- CVE-2025-0111Palo Alto Networks PAN-OS File Read Vulnerability
6.5 medium · over the network, with a basic account · CISA deadline was 13 Mar 25
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- SCP in mehreren Produkten: Mehrere Schwachstellen
WID-SEC-W-2023-1995 · 5 Oct
- jQuery: Mehrere Schwachstellen ermöglichen Cross-Site Scripting
WID-SEC-W-2022-1347 · 5 Oct
- SSH Protokoll: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
WID-SEC-W-2023-3174 · 16 Sept
- Palo Alto Networks PAN-OS: Mehrere Schwachstellen
WID-SEC-W-2026-3295 · 11 Sept
- Palo Alto Networks PAN-OS: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2026-2815 · 13 Aug
- OpenSSH: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
WID-SEC-W-2024-0872 · 30 Jul
- Palo Alto Networks PAN-OS: Mehrere Schwachstellen
WID-SEC-W-2026-2261 · 10 Jul
- Apache log4j: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2022-0351 · 8 Jul
PAN-OS at a glance
PAN-OS is the operating system on Palo Alto Networks firewalls, a mainstay in larger enterprises. Palo Alto ships PAN-OS releases plus security advisories; as a perimeter platform — and one that has seen actively exploited vulnerabilities — prompt patching is essential.
For admins the right combination of PAN-OS version and content updates matters, along with management/firewall (Panorama) compatibility. Never expose the management interface to the internet, apply advisories on a priority basis, and take a config snapshot before upgrading. On HA pairs follow the documented order, and read the known issues. After upgrading, verify VPN and critical policies. Track the PAN-OS version and its support lifecycle per platform; subscribe to Palo Alto's security advisories.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 12.2 | 12.2.3 | EOL 30 Jul 29 |
| 12.1 | 12.1.10 | EOL 28 Aug 28 |
| 11.2 | 11.2.15 | EOL 2 May 27 |
| 11.1 | 11.1.16-h2 | EOL 3 May 27 |
| 11.0 | 11.0.6-h1 | End of Life |
| 10.2 | 10.2.18-h10 | End of Life |
| 10.1 | 10.1.14-h20 | End of Life |
| 10.0 | 10.0.12-h6 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 12.2.3 | STABLE | 27/08/2026 | Release notes → |
| 12.2.2 | STABLE | 30/07/2026 | Release notes → |
| 12.1.8 | STABLE | 07/07/2026 | Release notes → |
| 12.1.7-h1 | STABLE | 22/06/2026 | Release notes → |
Frequently asked questions
- What is the latest version of PAN-OS?
- PAN-OS 12.2.3, released 27/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the PAN-OS release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new PAN-OS updates?
- Tick PAN-OS off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new PAN-OS version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current PAN-OS version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/pan-os)https://patchletter.com/badge/pan-os.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).