PAN-OS

CVE-2019-1579: Remote Code Execution in GlobalProtect Portal/Gateway Interface

Palo Alto Networks is aware of the reported remote code execution (RCE) vulnerability in its GlobalProtect portal and GlobalProtect Gateway interface products.

Published

ExploitedYes, in CISA KEVAdded 10 Jan 2022
Ransomware useKnownPer CISA
SeverityHIGHCVSS 3.1 8.1
EPSS46%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
PAN-OS 7.1 to 7.1.187.1.19 or later
PAN-OS 8.0 to 8.0.11-h18.0.12 or later
PAN-OS 8.1 to 8.1.28.1.3 or later

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Palo Alto Networks is aware of the reported remote code execution (RCE) vulnerability in its GlobalProtect portal and GlobalProtect Gateway interface products. The issue is already addressed in prior maintenance releases. (Ref: CVE-2019-1579) Successful exploitation of this issue allows an unauthenticated attacker to execute arbitrary code. This issue affects PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier releases. PAN-OS 9.0 is not affected.

Workarounds

If you have not already upgraded to the available updates listed above and cannot do so now, we recommend that you update to content release 8173, or the latest version, and confirm threat prevention is enabled and enforced on traffic that passes through the GlobalProtect portal and GlobalProtect Gateway interface.

Please see the customer advisory for more details here: https://live.paloaltonetworks.com/t5/Customer-Advisories/Action-Recommended-Recent-Security-Advisory-PAN-SA-2019-0020-Ref/ta-p/278505 .

You are not affected if you do not have GlobalProtect enabled.

Exploitation

CISA lists this CVE as exploited in the wild since 10 Jan 2022, including in ransomware campaigns.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.