CVE-2016-3657: Palo Alto Networks PAN-OS

Critical severity, CVSS 9.8. EPSS: 4.8% chance of exploitation in the next 30 days.

Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to cause a denial of service (device crash) or possibly execute arbitrary code via an SSL VPN request.

Affected products

  • Palo Alto Networks PAN-OS: from 5.0.0, before 5.0.18 (fixed in 5.0.18); from 5.1, before 5.1.11 (fixed in 5.1.11); from 6.0.0, before 6.0.13 (fixed in 6.0.13); from 6.1.0, before 6.1.10 (fixed in 6.1.10); from 7.0.0, up to and including 7.0.5

Published 2016-04-12. Last modified 2026-06-17.