← Vulnerability feed

Vulnerability record · CVE-2019-1579 · published 19 July 2019

CVE-2019-1579: PAN-OS GlobalProtect pre-auth remote code execution

Paloaltonetworks · Pan Os

PAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the GlobalProtect Portal or Gateway interface is enabled. An unauthenticated remote attacker can execute arbitrary code on the firewall, which sits at the network edge and is a high-value target. The record does not describe the exact vulnerable code path beyond the format string classification.

8.1 CVSS 3.1 High CISA KEV since 10 Jan 2022 Known ransomware use EPSS 46% · top 1.2% CWE-134 · CWE-134
8.1CVSS 3.1 base score, v2 6.8
46%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
12 Aug 2026Last modified by NVD

Description

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE on an edge firewall that is in CISA KEV with known ransomware use and very high EPSS.

What it is

PAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the GlobalProtect Portal or Gateway interface is enabled. An unauthenticated remote attacker can execute arbitrary code on the firewall, which sits at the network edge and is a high-value target. The record does not describe the exact vulnerable code path beyond the format string classification.

Impact

Successful exploitation gives the attacker arbitrary code execution on the PAN-OS device, typically at high privilege, allowing full compromise of the firewall and any traffic or credentials it handles. Because the device is an edge security control, compromise can expose the internal network.

Attack surface

Reachable over the network via the GlobalProtect Portal or Gateway interface when that service is enabled; the CVSS vector shows no privileges and no user interaction required. Only internet-exposed or otherwise reachable GlobalProtect interfaces are at risk.

Exploitation

CVE-2019-1579 is listed in CISA KEV with known ransomware campaign use, and EPSS is 0.46 (98.7th percentile), indicating active exploitation is expected. A public exploit write-up is referenced, so weaponized code is available.

What to do

  • Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory; 7.1.18, 8.0.11-h1 and 8.1.2 and earlier are affected.
  • If patching cannot be done immediately, disable the GlobalProtect Portal and Gateway interfaces or restrict access to them to trusted sources.
  • Place GlobalProtect interfaces behind access controls and monitor for anomalous requests to those endpoints.
  • Treat any internet-facing PAN-OS device running an affected version as potentially compromised and review it for signs of intrusion.
  • Track CISA KEV remediation due date (2022-07-10) and confirm closure.

Detection

  • Review PAN-OS and GlobalProtect logs for unexpected process execution, crashes or restarts on the firewall.
  • Monitor for unusual outbound connections or new listening services originating from the firewall itself.
  • Hunt for exploitation attempts against GlobalProtect endpoints in web or proxy logs, including malformed requests.
  • Check for unauthorized configuration changes, new admin accounts or persistence on PAN-OS devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-1579 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 July 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-1579 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed

Source: NIST National Vulnerability Database (record CVE-2019-1579), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.