
PAN-OS GlobalProtect: Command Injection (CVE-2024-3400)
An internet-facing Palo Alto Networks firewall published its GlobalProtect VPN portal to the world, and an unauthenticated command-injection flaw turned a single crafted request into code execution on the appliance. The attacker validated the bug with a zero-byte canary, stole the firewall's running configuration, dropped a python implant that takes commands from the device's own error log, and pivoted off the box into the domain controller. Reconstruct the chain from the firewall system, GlobalProtect, and perimeter traffic logs.
Launches in 5 days
Tuesday, October 13, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
6 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Oct 13, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free