Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

12 changes · newest first · grouped by dayCSVJSONRSS

SinceClear the filter
ChangedSourceRows
Counted changes from palo alto networks, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 21 Jul 2026· 1 change
2026-07-21Ransomware use confirmedCVE-2026-0257CISA KEVstated at publication Unknown, now states KnownTime to revision 53 days
Fri 29 May 2026· 1 change
2026-05-29Added to CISA KEVCVE-2026-0257CISA KEVfix due 2026-06-01Duration unknown
Wed 13 May 2026· 1 change
2026-05-13KEV required action changedCVE-2026-0300CISA KEVstated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required., now states Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.Time to revision 7 days
Wed 6 May 2026· 1 change
2026-05-06Added to CISA KEVCVE-2026-0300CISA KEVfix due 2026-05-09Duration unknown
Thu 2 Apr 2026· 2 changes
2026-04-02Product addedCVE-2025-0133palo_altonot named as affected at publication, now names cloud ngfwTime to revision 323 days
2026-04-02Product addedCVE-2025-0133palo_altonot named as affected at publication, now names prisma accessTime to revision 323 days
Wed 29 Oct 2025· 1 change
2025-10-29Ransomware use confirmedCVE-2024-9474CISA KEVstated at publication Unknown, now states KnownDuration unknown
Mon 23 Jun 2025· 1 change
2025-06-23Fix version movedCVE-2025-0138
palo alto networksprisma cloud compute edition
palo_alto
stated at publication 34.00.141, now states 34.01.129Release branch starts at 1.Time to revision 40 days
Mon 12 May 2025· 1 change
2025-05-12Ransomware use confirmedCVE-2024-0012CISA KEVstated at publication Unknown, now states KnownDuration unknown
Mon 7 Apr 2025· 1 change
2025-04-07Ransomware use confirmedCVE-2024-3400CISA KEVstated at publication Unknown, now states KnownDuration unknown
Wed 12 Mar 2025· 1 change
2025-03-12Fix version movedCVE-2025-0118
palo alto networksglobalprotect app
palo_alto
stated at publication 6.0.10, now states 6.0.11Release branch starts at 6.0.0.same dayTime to revision 0 days
Thu 20 Feb 2025· 1 change
2025-02-20Added to CISA KEVCVE-2025-0111CISA KEVfix due 2025-03-13Duration unknown

Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
4,561 record edits in the 52 weeks to 2026-09-07. Scroll for earlier dates.fewermore

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →