Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryperimeter-device-exposureembedded-device-vulnerabilityendpoint-software-vulnerability

Palo Alto Networks PAN-OS and Prisma Browser Vulnerabilities Disclosed

Updated 3mo agoFirst seen Nov 12, 20253 sources

Palo Alto Networks disclosed a denial-of-service (DoS) vulnerability, identified as CVE-2025-4619, affecting PAN-OS software on PA-Series, VM-Series, CN-Series firewalls, and Prisma Access. This vulnerability allows an unauthenticated attacker to reboot a firewall by sending specially crafted packets through the data plane, potentially causing the device to enter maintenance mode if exploited repeatedly. The company has detailed affected and unaffected PAN-OS versions and confirmed that Cloud NGFW is not impacted. Prisma Access customers have largely been upgraded, with remaining updates scheduled.

Additionally, Palo Alto Networks released its November 2025 monthly vulnerability update for Chromium and Prisma Browser, addressing multiple CVEs, including several Chromium vulnerabilities and three specific to Prisma Browser (CVE-2025-4616, CVE-2025-4617, CVE-2025-4618). The Canadian Centre for Cyber Security issued an advisory summarizing these disclosures and urging administrators to review the advisories, apply mitigations, and update affected products to secure their environments against these vulnerabilities.

Share:
Palo Alto Networks PAN-OS and Prisma Browser Vulnerabilities Disclosed
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 12, 20257mo ago

Canadian Centre for Cyber Security republishes Palo Alto advisory notice

The Canadian Centre for Cyber Security published alert AV25-748 referencing a Palo Alto Networks security advisory. This reflects government-side dissemination of Palo Alto's November 12, 2025 security advisory information.

Palo Alto Networks issues November 2025 Chromium and Prisma Browser update

Palo Alto Networks released advisory PAN-SA-2025-0018 covering the November 2025 monthly vulnerability update for Chromium and Prisma Browser. The publication indicates security fixes or vulnerability information for those products were made available on November 12, 2025.

Palo Alto Networks discloses CVE-2025-4619 PAN-OS DoS vulnerability

Palo Alto Networks published a security advisory for CVE-2025-4619 describing a PAN-OS firewall denial-of-service condition triggered by specially crafted packets. The advisory publicly documented the vulnerability on November 12, 2025.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.