January 10, 2022 · Applied Cybernetics Group
CVE-2019-1579 — Palo Alto Networks PAN-OS
known ransomware use
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
- Added to KEV
2022-01-10- Federal due date
2022-07-10- Vendor
- Palo Alto Networks
- Product
- PAN-OS
- EPSS
- 98.7th percentile (score 0.462, as of
2026-09-16) - NVD CVSS v3.1
- 8.1 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-1579
CISA short description
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
Required action
Apply updates per vendor instructions.
NVD description
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.