boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-9474MEDIUM
Palo Alto Networks Cloud NGFW — PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   N    6.9   .9477   99.9   YES
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         11.2.0 –     11.2.4-h1
  Prisma Access  unspecified  All
TIMELINE
  Oct 3   Reserved by palo_alto
  Nov 18  Added to CISA KEV, remediation due 2024-12-09
  Nov 18  Published (CNA: palo_alto)
  Aug 3   EXPLOIT PUBLISHED — CVE-2024-9474 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
  Aug 3   PATCH SHIPPED — CVE-2024-9474 (Palo Alto Networks Cloud NGFW). Fixed in Cloud NGFW All.
CWE-78 · CNA: palo_alto · CVSS v4.0 · 5 references · NVD status: Analyzed · KEV due December 9, 2024

Description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
October 3, 2024ReservedReserved by palo_alto
November 18, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-12-09
November 18, 2024PublishedPublished (CNA: palo_alto)
August 3, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2024-9474 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
August 3, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2024-9474 (Palo Alto Networks Cloud NGFW). Fixed in Cloud NGFW All.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Palo Alto NetworksCloud NGFWAll
Palo Alto NetworksPAN-OS11.2.011.2.4-h1
Palo Alto NetworksPrisma AccessAll

Weaknesses

CWE-78

References (5)

Related

Authoritative record: CVE-2024-9474 at cve.org

Vendors: palo alto networks

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-9474 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.