Skip to main content
Security

Chained Palo Alto CVEs expose 13,000 devices, revealing gaps in CVSS scoring

Chained Palo Alto CVEs expose 13,000 devices, revealing gaps in CVSS scoring Image: Primary
In November 2024, attackers gained unauthenticated remote admin access across more than 13,000 exposed Palo Alto Networks management interfaces by chaining two vulnerabilities that appeared manageable when scored separately. Palo Alto Networks scored CVE-2024-0012 at 9.3 and CVE-2024-9474 at 6.9 under CVSS v4.0. The 6.9 score fell below many enterprise patch thresholds because admin access appeared required. When combined, the authentication bypass eliminated that prerequisite entirely, allowing root access. "Adversaries circumvent severity ratings by chaining vulnerabilities together," Adam Meyers, senior vice president of Counter Adversary Operations at CrowdStrike, told VentureBeat in an interview on April 22, 2026. He described the operational psychology behind the missed chain: teams assessed each CVE independently, deprioritized the lower score, and queued the higher one for maintenance. Both CVEs sit on the CISA Known Exploited Vulnerabilities catalog. Neither score flagged the kill chain. The triage logic treated each CVE as an isolated event, as did the SLA dashboards and board reports those dashboards feed. CVSS was designed to score one vulnerability at a time. The problem is that adversaries do not attack one vulnerability at a time. Peter Chronis, former CISO of Paramount, wrote that CVSS base scores are theoretical measures of severity that ignore real-world context. By moving beyond CVSS-first prioritization at Paramount, Chronis reported reducing actionable critical and high-risk vulnerabilities by 90%. In 2025, 48,185 CVEs were disclosed, a 20.6% year-over-year increase. Jerry Gamblin, principal engineer at Cisco Threat Detection and Response, projects 70,135 for 2026. NIST announced on April 15 that CVE submissions have grown 263% since 2020, and the NVD will now prioritize enrichment for KEV and federal critical software only.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from VentureBeat and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Products
Security Products

Liquid sidechain pauses after reported 4,000 BTC withdrawal

Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...

Security Policy
Security Policy

Berlin reviews ransomware data release after rejecting ransom

Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...

Security Infrastructure
Security Infrastructure

JetBrains tells Cadence users to rotate credentials after TeamCity breach

JetBrains is telling Cadence users to revoke or rotate credentials and secrets after attackers exploited a critical TeamCity vulnerability to breach a Cadence environment. The company said the attackers accessed a 2024 server back...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...