Palo Alto Security Updates – 15 May 2025

Palo Alto has released security updates to fix multiple vulnerabilities affecting Palo Alto PAN-OS and Palo Alto Cortex XDR.

The addressed vulnerabilities could allow the attacker to perform denial-of-service attacks, bypass security restrictions, conduct cross-site scripting attacks, manipulate data, obtain sensitive information, execute arbitrary commands/codes, and gain access to the affected systems.

Sample of the addressed vulnerabilities:

Palo Alto Networks PAN-OS Denial of Service Vulnerability (CVE-2025-0128):

  • CVSS: 6.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Palo Alto Security Advisory

References