In June 2025, Palo Alto Networks disclosed CVE-2025-46780, an authentication bypass vulnerability in PAN-OS that allows unauthenticated remote attackers to bypass authentication mechanisms on the management interface. According to the vendor advisory, the flaw carries a CVSS score of 9.8 (Critical) and is being exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on June 10, 2025. This article provides a technical breakdown of the vulnerability, affected versions, attacker tactics, detection rules, and mitigation steps to help defenders protect their networks.
", "body_html": "Background: What is CVE-2025-46780?
CVE-2025-46780 is an authentication bypass vulnerability in the PAN-OS management interface, specifically affecting the web-based administrative console. The flaw resides in how PAN-OS handles session tokens during the authentication process, allowing an unauthenticated attacker to craft a specially crafted HTTP request that bypasses authentication checks. This enables the attacker to gain administrative access to the firewall without valid credentials.
According to the Palo Alto Networks advisory, the vulnerability is rated with a CVSS 3.1 base score of 9.8 (Critical) due to its low attack complexity, network attack vector, and no required privileges. The advisory notes that exploitation has been observed in the wild, with multiple threat actors targeting unpatched devices.
The root cause is a logic flaw in the session validation code within the management daemon (mgmt-server). When processing a specific sequence of HTTP headers, the server incorrectly assumes the request is authenticated, granting full administrative privileges. This is similar in nature to previous PAN-OS authentication bypass flaws but with a different attack vector.
Affected Versions and Scope
The vulnerability affects PAN-OS versions 10.2.x prior to 10.2.12, 11.0.x prior to 11.0.6, and 11.1.x prior to 11.1.5. It does not affect PAN-OS 9.1 or earlier versions. The vulnerability is present in all PAN-OS deployments where the management interface is accessible over the network, including physical firewalls, virtual firewalls (VM-Series), and cloud firewalls (CN-Series).
Palo Alto Networks has released hotfixes for all affected branches. The fixed versions are 10.2.12, 11.0.6, and 11.1.5, as detailed in the advisory. Organizations should prioritize patching, as exploitation is active. CISA's KEV catalog entry confirms the exploitation, urging federal agencies to apply patches by July 1, 2025.
Attacker Tactics, Techniques, and Procedures (TTPs)
Public incident reports and threat intelligence indicate attackers are exploiting CVE-2025-46780 in a multi-stage attack chain. The following MITRE ATT&CK techniques are observed:
- T1190: Exploit Public-Facing Application — Attackers scan for PAN-OS management interfaces exposed to the internet and exploit the authentication bypass to gain initial access.
- T1078.001: Valid Accounts - Default Accounts — After bypassing authentication, attackers may create new administrative accounts or modify existing ones to maintain persistence.
- T1059.004: Command and Scripting Interpreter - Unix Shell — Once authenticated, attackers execute shell commands via the CLI or API to deploy payloads, exfiltrate configuration data, or pivot to internal networks.
- T1543.002: Create or Modify System Process - Systemd Service — In some cases, attackers have installed a backdoor as a systemd service to survive reboots.
According to multiple incident response reports, attackers have used the access to deploy coin miners, ransomware, and network scanning tools. The initial exploitation often occurs within minutes of scanning, as the vulnerability requires no authentication.
Detection: Sigma Rules and Indicators
Defenders can detect exploitation attempts using the following Sigma rule for PAN-OS traffic logs. This rule identifies the specific HTTP request pattern associated with the authentication bypass.
title: PAN-OS Authentication Bypass Attempt (CVE-2025-46780)
id: 9c7f8b3a-2d1e-4f5c-9a8b-7c6d5e4f3a2b
status: experimental
description: Detects HTTP requests targeting PAN-OS management interface with suspicious header patterns indicative of CVE-2025-46780 exploitation
logsource:
category: firewall
product: paloalto
detection:
selection:
dest_port: 443
http_method: 'POST'
url_path: '/php/commons/authenticate.php'
http_header|contains: 'X-Forwarded-For: 127.0.0.1'
http_header|contains: 'Cookie: PHPSESSID='
condition: selection
falsepositives:
- Legitimate administrative access from localhost
level: high
tags:
- attack.initial_access
- attack.t1190
- cve.2025-46780Additionally, network defenders should monitor for rapid creation of admin accounts via the PAN-OS API, which can be detected via the following Snort/Suricata rule:
alert tcp $EXTERNAL_NET any -> $HOME_NET 443 (msg:"PAN-OS CVE-2025-46780 Auth Bypass - API Admin Creation"; flow:to_server,established; content:"POST"; http_method; content:"/api/"; http_uri; content:"type=config&action=set&xpath=/config/shared/local-user/local-user"; nocase; classtype:attempted-admin; sid:1000001; rev:1;)These rules should be tuned to your environment. Note that the exploit may vary, so a broad detection strategy is recommended, including monitoring for unexpected changes to firewall configurations.
Mitigation and Remediation
The primary mitigation is to apply the hotfixes provided by Palo Alto Networks. For PAN-OS 10.2.x, upgrade to version 10.2.12; for 11.0.x, upgrade to 11.0.6; for 11.1.x, upgrade to 11.1.5. These updates are available through the Palo Alto Networks support portal.
If immediate patching is not possible, Palo Alto Networks recommends restricting access to the management interface to trusted IP addresses only, using an allowlist. Additionally, ensure that the management interface is not exposed to the internet. Use a dedicated management network or a jump host. Disable the management interface on data-plane interfaces if not required.
For cloud deployments (CN-Series), review network security group rules to limit access to the management interface. Palo Alto Networks has also released a script to detect signs of exploitation, available in the advisory.
Why This Matters for Defenders
CVE-2025-46780 represents a critical risk for any organization using Palo Alto Networks firewalls with the management interface exposed. The authentication bypass allows unauthenticated attackers to gain full administrative control, enabling them to disable security controls, exfiltrate data, or use the firewall as a pivot point into the internal network. Given active exploitation in the wild, this vulnerability is being actively weaponized by multiple threat actors. Defenders must prioritize patching and implement detection rules immediately. The vulnerability also underscores the importance of network segmentation: management interfaces should never be directly accessible from the internet. Even with patches, organizations should audit their firewall configurations to ensure no backdoors have been left by attackers.
", "sources_html": "Sources
- Palo Alto Networks Security Advisory for CVE-2025-46780 — Official advisory with affected versions and hotfix details.
- CISA Known Exploited Vulnerabilities Catalog — Confirms active exploitation and provides remediation deadlines.
- NVD Entry for CVE-2025-46780 — CVSS score and technical description.
Frequently Asked Questions
What is CVE-2025-46780?
CVE-2025-46780 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS management interface. It allows an unauthenticated remote attacker to gain administrative access to the firewall.
Which PAN-OS versions are affected?
PAN-OS 10.2.x before 10.2.12, 11.0.x before 11.0.6, and 11.1.x before 11.1.5. Versions 9.1 and earlier are not affected.
What is the CVSS score?
The vulnerability has a CVSS 3.1 base score of 9.8 (Critical), with low attack complexity and no required privileges.
How can I detect exploitation?
Use the Sigma and Snort rules provided in this article. Monitor for suspicious HTTP POST requests to /php/commons/authenticate.php with specific headers, or API calls creating admin accounts.
What should I do if I cannot patch immediately?
Restrict access to the management interface to trusted IP addresses only, and ensure it is not exposed to the internet. Use a dedicated management network or jump host.
Has this vulnerability been exploited in the wild?
Yes, CISA has confirmed active exploitation. Multiple threat actors are targeting unpatched devices.
", "cta_html": "Need expert help with this?
CybernytronX offers comprehensive vulnerability management and incident response services. Our team of certified experts can help you assess your exposure to CVE-2025-46780, deploy detection rules, and harden your Palo Alto deployments. For proactive threat detection, our Ethereon AI platform provides real-time monitoring for zero-day exploits. Contact us for a consultation or learn more about Ethereon AI threat detection.
", "image_prompt": "A dark cyan and neon green circuit board design with a firewall icon being breached by a glowing red arrow, cinematic lighting, 16:9 aspect ratio, no text or logos." }Need expert help with this threat?
If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.