CVE-2024-3400
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
15 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.32%
probability
This CVE has a 94.32% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
W01fh4cker/CVE-2024-3400-RCE-Scan
CVE-2024-3400-RCE
90
0x0d3ad/CVE-2024-3400
CVE-2024-3400
71
Chocapikk/CVE-2024-3400
PoC CVE-2024-3400 — Chocapikk/CVE-2024-3400
15
momika233/CVE-2024-3400
PoC CVE-2024-3400 — momika233/CVE-2024-3400
13
Yuvvi01/CVE-2024-3400
PoC CVE-2024-3400 — Yuvvi01/CVE-2024-3400
11
ak1t4/CVE-2024-3400
Global Protec Palo Alto File Write Exploit
9
AdaniKamal/CVE-2024-3400
CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect
7
schooldropout1337/CVE-2024-3400
PoC CVE-2024-3400 — schooldropout1337/CVE-2024-3400
6
8 repos — triés par ⭐
Rechercher sur GitHub ↗
Cybersecurity Threat Landscape 2024 Midyear Review
Qualys
Aug 06, 2024
Palo Alto Networks fixes zero-day exploited to backdoor firewalls
BleepingComputer
Apr 15, 2024
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Over 2,000 Palo Alto firewalls hacked using recently patched bugs
BleepingComputer
Nov 21, 2024
Security Advisory 2024-037
CERT-EU
Apr 29, 2024
Signal Intelligence
Confidence
95%
EPSS
94.32%
Mentions
15
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2024-3400 is explicitly named as a zero-day exploited in the wild to backdoor Palo Alto Networks firewalls, with patch released in April 2024 coinciding with exploitation disclosure. BleepingComputer article title directly states 'zero-day exploited to backdoor firewalls,' and follow-up reporting confirms over 2,000 firewalls were compromised using this vulnerability, establishing active exploitation prior to or concurrent with patch availability.
Threat Actors 66
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
Turla Group
apt_group
Information theft and espionage
Russian Federation
Void Arachne
apt_group
Information theft and espionage
🇨🇳 CN
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
DarkHotel
apt_group
Information theft and espionage
🇰🇷 KR
Mustang Panda
apt_group
Information theft and espionage
🇨🇳 CN
Cobalt
apt_group
Financial crime
🇷🇺 RU
FIN7
apt_group
Financial crime
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Vicious Panda
apt_group
Information theft and espionage
🇨🇳 CN
TeamPcp
apt_group
Harvester
apt_group
Information theft and espionage
Unknown
Hacking Team
apt_group
🇮🇹 IT
GhostEmperor
apt_group
Information theft and espionage
🇨🇳 CN
NoName057
apt_group
🇷🇺 RU
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
Sea Turtle
apt_group
Information theft and espionage
🇹🇷 TR
Tick
apt_group
Information theft and espionage
🇨🇳 CN
APT3
apt_group
Information theft and espionage
🇨🇳 CN
ELECTRUM
apt_group
Information theft and espionage
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Just Evil
apt_group
🇷🇺 RU
Volt Typhoon
apt_group
Information theft and espionage
🇨🇳 CN
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
BRONZE HIGHLAND
apt_group
Information theft and espionage
🇨🇳 CN
ArcaneDoor
apt_group
🇨🇳 CN
Silence group
apt_group
Financial crime
🇷🇺 RU
Storm-2077
apt_group
Information theft and espionage
🇨🇳 CN
Cuboid Sandstorm
apt_group
🇮🇷 IR
Tortoiseshell
apt_group
Information theft and espionage
🇮🇷 IR
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
RomCom
apt_group
Financial gain
🇷🇺 RU
UNC5174
apt_group
🇨🇳 CN
Earth Estries
apt_group
Information theft and espionage
🇨🇳 CN
HAFNIUM
apt_group
Information theft and espionage
🇨🇳 CN
BrazenBamboo
apt_group
🇨🇳 CN
Fox Kitten
apt_group
Information theft and espionage
🇮🇷 IR
Gray Sandstorm
apt_group
🇮🇷 IR
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Actor240524
apt_group
Flax Typhoon
apt_group
Information theft and espionage
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
Void Rabisu
apt_group
Financial gain
🇷🇺 RU
UNC4841
apt_group
Information theft and espionage
🇨🇳 CN
UTA0218
apt_group
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Water Bakunawa
apt_group
🇷🇺 RU
Bitwise Spider
apt_group
Financial gain
🇷🇺 RU
Red October
apt_group
🇷🇺 RU
Circles
apt_group
Global
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Operation Digital Eye
apt_group
Information theft and espionage
🇨🇳 CN
PassCV
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Operation Olympic Games
apt_group
Sabotage and destruction
🇺🇸 US
Mana Team
apt_group
🇨🇳 CN
Iron Group
apt_group
Information theft and espionage
🇨🇳 CN
puNK-003
apt_group
🇰🇵 KP
Operation Shadow Force
apt_group
🇨🇳 CN
TA4903
apt_group
🇺🇸 US
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Dark Partners
apt_group
Triage Info
Decided atMar 05, 2026