Alerts
Events
DCR
Explore Cyware Products
Alerts
Events
DCR
Go to listing page
Critical Vulnerability in Palo Alto GlobalProtect Gateway & Portal Enables Remote Code Execution
Malware and Vulnerabilities
May 21, 2025
gbhackers
A reflected XSS vulnerability in Palo Alto Networks' GlobalProtect gateway and portal allows execution of malicious JavaScript in authenticated users' browsers, posing phishing and credential theft risks, especially with Clientless VPN enabled.
Read More
Palo Alto Networks
PAN-OS
GlobalProtect
CVE-2025-0133
Cross Site Scripting
Publisher
Previous
Researchers Expose PWA JavaScript Attack That Redirects ...
Threat Intel & Info Sharing
Next
Scattered Spider snared financial orgs before retail
Threat Actors