boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Palo Alto Networks

Vendor reference — Palo Alto Networks · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow Palo Alto Networks — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs4937
KEV entries142
Rate & severity
KEV/100Med CVSSMed EPSSCHML
28.64.7.0022122212

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▄▂▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▇

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-052
2026-069
2026-0714
2026-0812

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2024-3400100.0YES2024-04-12
CVE-2024-00129.3100.0CRITICALYES2024-11-18
CVE-2024-946599.9YES2024-11-14
CVE-2024-946399.9YES2024-11-14
CVE-2025-010899.9YES2025-02-18
CVE-2017-1594499.9YES2022-08-18
CVE-2024-94746.999.9MEDIUMYES2024-11-18
CVE-2026-025799.8YES2026-05-29
CVE-2024-591099.8YES2024-11-07
CVE-2026-030098.2YES2026-05-06
CVE-2024-339398.0YES2024-12-30
CVE-2020-202190.5YES2022-03-25
CVE-2022-002882.5YES2022-08-22
CVE-2025-011178.7YES2025-02-20
CVE-2026-02736.169.0MEDIUM2026-06-10

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-03011.724.1LOW2026-08-13
CVE-2026-02995.99.3MEDIUM2026-08-13
CVE-2026-02985.28.8MEDIUM2026-08-13
CVE-2026-02975.26.1MEDIUM2026-08-13
CVE-2026-02964.50.6MEDIUM2026-08-13
CVE-2026-02954.10.3MEDIUM2026-08-13
CVE-2026-02946.02.3MEDIUM2026-08-13
CVE-2026-02935.61.6MEDIUM2026-08-13
CVE-2026-02922.14.2LOW2026-08-13
CVE-2026-02911.12.2LOW2026-08-13
CVE-2026-02900.54.0LOW2026-08-13
CVE-2026-02890.55.5LOW2026-08-13
CVE-2026-02876.625.2MEDIUM2026-07-09
CVE-2026-02866.064.6MEDIUM2026-07-09
CVE-2026-02854.713.9MEDIUM2026-07-09

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
PAN-OS2611
Cloud NGFW172
Prisma Access172
Prisma Access Agent80
GlobalProtect App60
Expedition33
Prisma Browser30
Panorama20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-02572026-05-2999.8
CVE-2026-03002026-05-0698.2
CVE-2025-01112025-02-2078.7
CVE-2025-01082025-02-1899.9
CVE-2024-33932024-12-3098.0
CVE-2024-94742024-11-186.999.9MEDIUM
CVE-2024-00122024-11-189.3100.0CRITICAL
CVE-2024-94632024-11-1499.9
CVE-2024-94652024-11-1499.9
CVE-2024-59102024-11-0799.8
CVE-2024-34002024-04-12100.0
CVE-2022-00282022-08-2282.5
CVE-2017-159442022-08-1899.9
CVE-2020-20212022-03-2590.5

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2020-20212022-04-151587
CVE-2017-159442022-09-081441
CVE-2022-00282022-09-121437
CVE-2024-34002024-04-19852
CVE-2024-59102024-11-28629
CVE-2024-94652024-12-05622
CVE-2024-94632024-12-05622
CVE-2024-00122024-12-09618
CVE-2024-94742024-12-09618
CVE-2024-33932025-01-20576

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.