Palo Alto Networks has issued a patch for the buffer overflow vulnerability, CVE-2021-3064, which ranks a 9.8 on the CVSS v3.1 scale. The vulnerability affects PAN-OS 8.1.17 and prior, which is the operating system for the Global Protect VPN portal or gateway has been enabled. The flaw could enable an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. Randori defended its actions, saying it ethically used the vulnerability information to develop an exploit.”]
Source: https://www.bankinfosecurity.com/firm-held-onto-palo-alto-vpn-zero-day-for-11-months-a-17898

