Palo Alto: β€œLOL, we fixed 24 vulns in a random Tuesday update with no CVE alert. Why are you panicking?”

https://security.paloaltonetworks.com/PAN-SA-2025-0012

  • No alerts
  • No heads-up

Just a stealth patch buried in the advisory feed.

The stats:

  • 24 total CVEs
  • 11 High, 11 Medium
  • 100% discovered externally
  • Average patch delay: 4 FUCKING years for high severity

All bundled into one advisory.
Welcome to the Patch Gacha Machine:
Spin once, fix 24 vulnerabilities (maybe).

PAN CVEs age like wine… and compromise like whiskey.

#PANOS #CyberSecurity #CVEs #PatchAndPray #SilentFixes #PSIRTFail #MemeSec #BlueTeamLife #TrustButVerify

PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any signif...

Palo Alto Networks Product Security Assurance