boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Palo Alto Networks

Vendor reference — Palo Alto Networks · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow Palo Alto Networks — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs5746
KEV entries132
Rate & severity
KEV/100Med CVSSMed EPSSCHML
22.85.2.0029782715

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▁▁▂▂▂▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▇▆▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-052
2026-069
2026-0714
2026-0812
2026-099
2026-100

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2024-340010.0100.0CRITICALYES2024-04-12
CVE-2024-00129.3100.0CRITICALYES2024-11-18
CVE-2024-94659.299.9CRITICALYES2024-10-09
CVE-2024-94639.999.9CRITICALYES2024-10-09
CVE-2025-01088.899.9HIGHYES2025-02-12
CVE-2026-02577.899.9HIGHYES2026-05-13
CVE-2024-94746.999.9MEDIUMYES2024-11-18
CVE-2024-59109.399.8CRITICALYES2024-07-10
CVE-2026-03009.398.3CRITICALYES2026-05-06
CVE-2024-33938.798.1HIGHYES2024-12-27
CVE-2020-202110.091.0CRITICALYES2020-06-29
CVE-2022-00288.684.5HIGHYES2022-08-10
CVE-2025-01117.180.0HIGHYES2025-02-12
CVE-2026-02866.076.0MEDIUM—2026-07-09
CVE-2026-02736.170.3MEDIUM—2026-06-10

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-03107.228.7HIGH—2026-09-10
CVE-2026-03094.036.7MEDIUM—2026-09-10
CVE-2026-03075.91.0MEDIUM—2026-09-10
CVE-2026-03044.811.1MEDIUM—2026-09-10
CVE-2026-03021.155.9LOW—2026-09-10
CVE-2026-03054.30.8MEDIUM—2026-09-10
CVE-2026-03081.116.7LOW—2026-09-10
CVE-2026-03065.81.0MEDIUM—2026-09-10
CVE-2026-03032.47.7LOW—2026-09-10
CVE-2026-03011.722.3LOW—2026-08-13
CVE-2026-02995.99.3MEDIUM—2026-08-13
CVE-2026-02985.224.4MEDIUM—2026-08-13
CVE-2026-02975.221.6MEDIUM—2026-08-13
CVE-2026-02964.52.7MEDIUM—2026-08-13
CVE-2026-02954.10.1MEDIUM—2026-08-13

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-02572026-05-297.899.9HIGH
CVE-2026-03002026-05-069.398.3CRITICAL
CVE-2025-01112025-02-207.180.0HIGH
CVE-2025-01082025-02-188.899.9HIGH
CVE-2024-33932024-12-308.798.1HIGH
CVE-2024-94742024-11-186.999.9MEDIUM
CVE-2024-00122024-11-189.3100.0CRITICAL
CVE-2024-94632024-11-149.999.9CRITICAL
CVE-2024-94652024-11-149.299.9CRITICAL
CVE-2024-59102024-11-079.399.8CRITICAL
CVE-2024-34002024-04-1210.0100.0CRITICAL
CVE-2022-00282022-08-228.684.5HIGH
CVE-2020-20212022-03-2510.091.0CRITICAL

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2020-20212022-04-151634
CVE-2022-00282022-09-121484
CVE-2024-34002024-04-19899
CVE-2024-59102024-11-28676
CVE-2024-94652024-12-05669
CVE-2024-94632024-12-05669
CVE-2024-00122024-12-09665
CVE-2024-94742024-12-09665
CVE-2024-33932025-01-20623
CVE-2025-01082025-03-11573

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.