Malware & Threats

Palo Alto Patches Firewall Zero-Day Exploited in Operation Lunar Peek

Palo Alto Networks has released patches and CVEs for the firewall zero-days exploited in what the company calls Operation Lunar Peek.

Palo Alto Networks on Monday released patches and assigned CVE identifiers for the firewall zero-days that have been exploited in what the company is tracking as Operation Lunar Peek.

The security firm reported learning about a potential zero-day in early November — possibly after seeing a sales offer on a cybercrime forum — and confirmed in-the-wild exploitation of a new vulnerability on November 15. 

On Monday, the cybersecurity giant informed customers that two PAN-OS vulnerabilities have been exploited in these attacks, which targeted “a limited number of management web interfaces that are exposed to internet traffic coming from outside the network”.

One of the zero-days is CVE-2024-0012, a critical authentication bypass flaw that allows an unauthenticated attacker who has access to the PAN-OS management interface to gain admin privileges.

An attacker can “perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474”.

CVE-2024-9474 is the second zero-day apparently spotted in the same attacks. This security hole has been described as a medium-severity privilege escalation issue that allows an attacker who has admin permissions to gain root privileges on the firewall.

Advertisement. Scroll to continue reading.

The vulnerabilities have been patched with the release of updates for PAN-OS 11.2, 11.1, 11.0, 10.2 and 10.1. Ensuring that the firewall’s management interface is only accessible from trusted internal IP addresses significantly lowers the risk of exploitation. 

The Shadowserver Foundation on Monday reported seeing over 6,600 IPs associated with internet-exposed PAN-OS interfaces, down from 11,000 IPs one week ago. 

Palo Alto is tracking the activity as Operation Lunar Peek, but it has not shared any information on the threat actor behind the attacks. It has, however, shared indicators of compromise (IoCs), including IP addresses and a hash associated with a PHP webshell payload dropped on hacked firewalls.

“This activity has primarily originated from IP addresses known to proxy/tunnel traffic for anonymous VPN services,” the cybersecurity firm noted.

The cybersecurity agency CISA has added CVE-2024-0012 and CVE-2024-9474 to its Known Exploited Vulnerabilities (KEV) catalog, urging government organizations to address the flaws by December 9.

Related: Thousands of Palo Alto Firewalls Potentially Impacted by Exploited Vulnerability

Related: State-Sponsored Hackers Exploit Zero-Day to Backdoor Palo Alto Networks Firewalls

Related: Palo Alto Networks Patches Unauthenticated Command Execution Flaw in Cortex XSOAR

Related Content

Vulnerabilities

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

Vulnerabilities

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.

Mobile & Wireless

Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.

Vulnerabilities

CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation.

Vulnerabilities

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.

Malware & Threats

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.

Email Security

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version