CVE-2024-3400: listed in the CISA KEV catalog

CVE-2024-3400 · CVSS 10.0 CRITICAL · EPSS 100.0% · KEV 2024-04-12

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Is CVE-2024-3400 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2024-3400

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.