CISA and Palo Alto Networks Alert on Active Exploitation of Firewall Vulnerabilities

TL;DR
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged two critical vulnerabilities in Palo Alto Networks' Expedition software, which are being actively exploited. These flaws, CVE-2024-9463 and CVE-2024-9465, could allow attackers to execute arbitrary OS commands or access sensitive data. Federal agencies are required to update their systems by December 5, 2024. Palo Alto Networks has released patches and is investigating a new remote command execution vulnerability affecting some firewall interfaces.
Topics:businessnetwork-security#cisa#cybersecurity#exploitation#network-security#palo-alto-networks#vulnerabilities
- CISA Flags Two Actively Exploited Palo Alto Flaws; New RCE Attack Confirmed The Hacker News
- Palo Alto Networks Confirms New Firewall Zero-Day Exploitation SecurityWeek
- CISA warns of more Palo Alto Networks bugs exploited in attacks BleepingComputer
- Palo Alto Networks’ customer migration tool hit by trio of CVE exploits Yahoo Finance
- Palo Alto Warns of Hackers Exploiting RCE Flaw in Firewall Management Interfaces CybersecurityNews
Want the full story? Read the original reporting
Read on The Hacker News