CISA Orders Federal Agencies to Patch Palo Alto Firewall Flaw Being Exploited Now
A misconfigured URL filtering setting in Palo Alto Networks firewall software is letting attackers weaponise the firewalls themselves, turning them into unwitting cannons pointed at other targets.

Key points
- CVE-2022-0028, a high-severity flaw in Palo Alto Networks' PAN-OS firewall software, was added to CISA's Known Exploited Vulnerabilities Catalog in August 2022.
- U.S. Federal agencies were ordered to apply patches by September 9, 2022.
- The bug affects PA-Series hardware, VM-Series virtual firewalls, and CN-Series container firewalls across six PAN-OS version lines.
- Palo Alto Networks says the vulnerable configuration is uncommon and likely set up by mistake, not by design.
- Patches are available now for all affected versions.
Palo Alto Networks makes the firewall equipment used by governments, hospitals and businesses worldwide. This month, researchers found a flaw serious enough that the U.S. Cybersecurity and Infrastructure Security Agency, the federal body that coordinates the country's cyber defences, issued an urgent public warning.
The bug, tracked as CVE-2022-0028, lives in PAN-OS, the operating system that runs Palo Alto's firewalls. Without ever logging in or proving any identity, a remote attacker can trick a vulnerable firewall into firing a flood of junk traffic at a target of their choosing. That technique is called a reflected and amplified denial-of-service attack. Think of it like redirecting a firehose: the attacker gives the firewall the address of a victim, and the firewall does the flooding.
How did the hackers get in?
They didn't need to. The flaw doesn't require breaking into the firewall, only that it has a specific URL filtering setting switched on in a particular way. URL filtering is a feature that blocks employees from visiting certain categories of website. If an administrator attached one or more blocked categories to a security rule with an external-facing network interface, the firewall becomes vulnerable. Palo Alto Networks believes most administrators didn't intend to create this configuration; it appears to be an accidental by-product of common setup steps.
Six version lines of PAN-OS carry this flaw. Fixed versions are PAN-OS 10.2.2-h2, 10.1.6-h6, 10.0.11-h1, 9.1.14-h4, 9.0.16-h3, and 8.1.23-h1. Anything older needs updating now.
CISA added CVE-2022-0028 to its Known Exploited Vulnerabilities Catalog, a curated list of flaws confirmed to be actively abused in the real world, on a Monday in late August. Federal agencies had until September 9, 2022 to patch. CISA also strongly recommends private businesses treat the list as a priority queue, a posture our June directive story covered when the guidance was formalised.
Should you worry?
The practical danger isn't data theft. Your firewall could be drafted into someone else's attack, hammering a third party's website offline without your knowledge. Businesses hit by that flood of traffic lose revenue and customer access. This is the same family of amplification technique we tracked in Palo Alto's GlobalProtect auth bypass coverage, where a misconfiguration opens a door the vendor assumed would stay shut.
Check your PAN-OS version and apply the patch. If a third-party provider manages your firewalls, ask them directly whether it's been applied.



