Every change, newest first
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on. | Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Tue 21 Jul 2026· 1 change | |||||
| 2026-07-21 | Ransomware use confirmed | CVE-2026-0257 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Unknown, now states Known | Time to revision 53 days |
| Fri 29 May 2026· 1 change | |||||
| 2026-05-29 | Added to CISA KEV | CVE-2026-0257 | Palo Alto NetworksPAN-OS CISA KEV | fix due 2026-06-01 | Duration unknown |
| Wed 13 May 2026· 1 change | |||||
| 2026-05-13 | KEV required action changed | CVE-2026-0300 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required., now states Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch. | Time to revision 7 days |
| Wed 6 May 2026· 1 change | |||||
| 2026-05-06 | Added to CISA KEV | CVE-2026-0300 | Palo Alto NetworksPAN-OS CISA KEV | fix due 2026-05-09 | Duration unknown |
| Wed 29 Oct 2025· 1 change | |||||
| 2025-10-29 | Ransomware use confirmed | CVE-2024-9474 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Mon 12 May 2025· 1 change | |||||
| 2025-05-12 | Ransomware use confirmed | CVE-2024-0012 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Mon 7 Apr 2025· 1 change | |||||
| 2025-04-07 | Ransomware use confirmed | CVE-2024-3400 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Thu 20 Feb 2025· 1 change | |||||
| 2025-02-20 | Added to CISA KEV | CVE-2025-0111 | Palo Alto NetworksPAN-OS CISA KEV | fix due 2025-03-13 | Duration unknown |
Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →