Vulnerability Intelligence Report
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
CVE-2019-1579
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
8.1
HIGH
Exploitability:2.3
Impact Score:5.9
EPSS Probability:45.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-134 ↗CWE-134 Use of Externally-Controlled Format String
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| n/a | Palo Alto Networks GlobalProtect Portal/Gateway Interface | PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier releases (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Palo Alto Networks, Inc. · Vendor · USA |
| Reserved | 2018-12-06T00:00:00 |
| Published | 2019-07-19T21:12:19 |
| Last Updated | 2026-08-12T03:55:54 |
Community Chatter & Buzz