Palo Alto Networks warns that the vulnerability CVE-2025-0111 is actively exploited with two other flaws to compromise PAN-OS firewalls.
The vulnerability CVE-2025-0111 is a file read issue in PAN-OS, allowing an attacker to read files that are readable by the 'nobody' user.
Palo Alto Networks has observed exploit attempts chaining CVE-2025-0108 with CVE-2024-9474 and CVE-2025-0111 on unpatched PAN-OS web management interfaces.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the CVE-2025-0108 vulnerability to its Known Exploited Vulnerabilities catalog.