CVE-2019-1579: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2022-01-10. EPSS: 46.2% chance of exploitation in the next 30 days.

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

Affected products

  • Palo Alto Networks PAN-OS: before 7.1.19 (fixed in 7.1.19); from 8.0.0, before 8.0.12 (fixed in 8.0.12); from 8.1.0, before 8.1.3 (fixed in 8.1.3)

Published 2019-07-19. Last modified 2026-10-02.