Palo Alto Networks addressed a critical vulnerability where two individually low-severity CVEs, when chained together, enabled root access to approximately 13,000 devices. The incident reveals a significant gap in CVSS vulnerability scoring methodology, which failed to account for attack chain scenarios.
Safety
CVSS scored these two Palo Alto CVEs as manageable. Chained, they gave attackers root access to 13,000 devices.
Two individually low-severity Palo Alto vulnerabilities exploited CVSS's blind spot for attack chains, giving attackers root access to 13,000 devices and exposing a critical flaw in industry vulnerability triage.
Friday, April 24, 2026 12:00 PM UTC2 MIN READSOURCE: VentureBeatBY sys://pipeline
Tags
safety
/// RELATED