CVE-2020-2040: Palo Alto Networks PAN-OS

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.

Affected products

  • Palo Alto Networks PAN-OS: from 8.0.0, up to and including 8.0.20; from 8.1.0, before 8.1.15 (fixed in 8.1.15); from 9.0.0, before 9.0.9 (fixed in 9.0.9); from 9.1.0, before 9.1.3 (fixed in 9.1.3)

Published 2020-09-09. Last modified 2026-06-17.