PAN-OS GlobalProtect Endpoint Probe (CVE-2024-3400) for 2026-07-27
Jul 27, 2026
WebExploit
Last Updated: 12:00 UTC
CVE-2024-3400 is a command injection in Palo Alto PAN-OS GlobalProtect (CVSS 10.0) allowing unauthenticated RCE via the prelogin endpoint. Exploitation was observed in the wild before the patch was available. Scanners probe /global-protect/prelogin.esp and /login.esp to fingerprint GlobalProtect gateways prior to exploitation.
CVE References
MITRE ATT&CK
Tactic: Initial Access (TA0001)
Technique: T1190 — Exploit Public-Facing Application
Observed URIs
Attackers by Country
| Kazakhstan | 1 | 50.0% |
| Romania | 1 | 50.0% |
IP Address : ASN : City/Provider
-
185.136.15.2 : AS49393 solutions factory ltd. : Kazakhstan
-
45.142.193.149 : AS35478 bunea telecom srl : Romania