CRITICALZero Day
Verified
Global

Critical Zero-Day in Palo Alto PAN-OS Firewalls Under Active Mass Exploitation

·Source: Palo Alto Networks PSIRT

Updated:

Executive Summary

A critical unauthenticated RCE in PAN-OS GlobalProtect is being mass exploited. Over 25,000 devices vulnerable. CISA issues emergency directive.

Analysis

Palo Alto Networks has confirmed active exploitation of CVE-2026-0015, a critical command injection vulnerability in the GlobalProtect gateway. Unauthenticated attackers can execute arbitrary commands as root via crafted HTTPS requests. Volexity first observed exploitation on March 26 with rapid escalation. CISA issued Emergency Directive 26-02 requiring federal agencies to patch within 48 hours.

Timeline

Discovered
Mar 26, 2026
Exploitation Detected
Mar 26, 2026
Published
Mar 31, 2026
Patch Available
Mar 30, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-0015
Source Attribution

Originally published by Palo Alto Networks PSIRT on Mar 31, 2026. Verified by: CISA, Palo Alto Networks, Volexity.

Related Threats

CRITICALZero Day

The AI app builder your team trusts has a root-level backdoor

The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate AI-powered workflows without writing much code — are landing in production environments faster than security teams can assess them. They connect to your APIs, your databases, your cloud credentials and yo

CVE-2026-0768CVE-2026-0769
CSO Online
CRITICALZero Day

ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics

A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters reported that a suspected member of ShinyHunters had been arrested by the FBI and has been cooperating

CVE-2026-35273
CSO Online
CRITICALZero Day

Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal , is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the F

CVE-2026-35273
CSO Online