Palo Alto's Firewall Glitch Hits CISA's 'Fix Now' List After Real-World Attacks
CISA's Known Exploited Vulnerabilities catalog just grew by one: a Palo Alto firewall bug that's already drawing fire from attackers. Patch by September 9, or risk becoming the next DDoS reflector.
Threat DigestApr 03, 20264 min read26 views
⚡ Key Takeaways
CISA added CVE-2022-0028 to KEV catalog after confirmed exploits; federal patch deadline is Sept 9.𝕏
Bug turns misconfigured PAN-OS firewalls into DDoS amplifiers — no auth needed.𝕏
Vendors like Palo Alto downplay scope, but history shows 'niche' flaws enable massive attacks.𝕏
The 60-Second TL;DR
CISA added CVE-2022-0028 to KEV catalog after confirmed exploits; federal patch deadline is Sept 9.
Bug turns misconfigured PAN-OS firewalls into DDoS amplifiers — no auth needed.
Vendors like Palo Alto downplay scope, but history shows 'niche' flaws enable massive attacks.