CVE-2019-1566: Palo Alto Networks PAN-OS

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.

Affected products

  • Palo Alto Networks PAN-OS: from 7.1.0, before 7.1.22 (fixed in 7.1.22); from 8.0.0, before 8.0.15 (fixed in 8.0.15); from 8.1.0, before 8.1.6 (fixed in 8.1.6)

Published 2019-01-30. Last modified 2026-06-17.