Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
REVIEWED ORIGINAL-SOURCE CLAIMOFFICIAL VENDOR SOURCEREVIEWED 14 SEP 2026

Palo Alto Networks · EDITORIAL PRIMARY-SOURCE REVIEW

Palo Alto Networks Expedition Expedition 1 and 2

Palo Alto Networks Expedition is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This claim was manually scoped and reviewed against the linked original publisher statement. It applies only to the named release and support phase. Confirm edition, device and contract applicability before acting.

Claim scope: Palo Alto Networks Expedition migration tool, including both Expedition 1 and Expedition 2. Does not apply to Palo Alto Networks firewalls, PAN-OS, Panorama or other services.

Reviewed 14 Sep 2026.

Product overview

Palo Alto Networks Expedition is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductPalo Alto Networks Expedition
ReleaseExpedition 1 and 2
End of End of life31 December 2024
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 5 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2024-9465Added 14 Nov 2024

Palo Alto Networks Expedition SQL Injection Vulnerability

Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

Palo Alto Networks · ExpeditionRansomware use: Unknown

CISA entry
CVE-2024-9463Added 14 Nov 2024

Palo Alto Networks Expedition OS Command Injection Vulnerability

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Palo Alto Networks · ExpeditionRansomware use: Unknown

CISA entry
CVE-2024-5910Added 7 Nov 2024

Palo Alto Networks Expedition Missing Authentication Vulnerability

Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.

Palo Alto Networks · ExpeditionRansomware use: Unknown

CISA entry

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYReady

Palo Alto Networks Expedition official lifecycle source

Expedition reached its End of Life (EoL) date on December 31, 2024.

Official vendor lifecycle or product-change property. Extracted records require human review.

Original-source claim reviewed 14 Sep 2026

Open official vendor source