CVE-2024-0010: Palo Alto Networks PAN-OS

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.

Affected products

  • Palo Alto Networks PAN-OS: from 10.1.0, before 10.1.11 (fixed in 10.1.11); version 10.1.11 only; from 9.1.0, before 9.1.17 (fixed in 9.1.17); from 9.0.0, before 9.0.17 (fixed in 9.0.17); version 9.0.17 only

Published 2024-02-14. Last modified 2026-06-17.