Conexus LLC v. Palo Alto Networks: Injection Exploit Patent Dismissed in 7 Days
Conexus LLC filed a patent infringement action against cybersecurity giant Palo Alto Networks in Delaware, asserting US11736499B2 covering systems and methods for detecting injection exploits. The case was voluntarily dismissed with prejudice by the plaintiff just 7 days after filing — one of the shortest lifespan cases on record in D. Del.
A 7-Day Patent Suit Against Palo Alto Networks That Never Got Started
On July 17, 2025, Conexus LLC filed a patent infringement complaint against Palo Alto Networks, Inc. in the United States District Court for the District of Delaware, asserting US11736499B2 — a patent directed to systems and methods for detecting injection exploits. Palo Alto Networks is one of the world’s largest publicly traded cybersecurity companies, making it a high-profile target for patent assertion. The case was assigned to Judge Jennifer L. Hall and styled as Case No. 1:25-cv-00890.
Just seven days after the complaint was filed, on July 24, 2025, Conexus LLC filed a notice of voluntary dismissal with prejudice under Federal Rule of Civil Procedure 41(a)(1)(A)(i). Because the notice was filed before Palo Alto Networks served either an answer or a motion for summary judgment, court approval was not required. The dismissal with prejudice extinguishes Conexus’s ability to refile the same claims against Palo Alto Networks on this patent, and each party was ordered to bear its own costs and fees.
A dismissal of this speed — seven days, no docketed defendant appearance — is unusual even by the standards of assertive patent litigation in Delaware. The public record does not disclose whether the parties reached a private settlement, a licensing arrangement, or whether Conexus identified a filing error or strategic reason to withdraw. The with-prejudice designation and mutual cost-bearing language are consistent with a negotiated resolution, but that remains speculative on the available record.
Filing to Dismissed with Prejudice in 7 days
7 days — well below the D. Del. median; case closed before service was likely completed
Dismissed with prejudice: what the Rule 41 exit means for both sides
Rule 41(a)(1)(A)(i): plaintiff’s unilateral exit before answer
Under FRCP 41(a)(1)(A)(i), a plaintiff may dismiss an action without court order by filing a notice before the defendant serves an answer or motion for summary judgment. Conexus invoked this rule but elected dismissal with prejudice — a voluntary choice that carries the same res judicata effect as a judgment on the merits. No judicial approval was needed, and none was sought.
Procedural: Rule 41(a)(1)(A)(i)With prejudice: Conexus cannot refile against Palo Alto Networks on this patent
A dismissal with prejudice operates as a final adjudication on the merits, permanently barring Conexus from asserting US11736499B2 against Palo Alto Networks. This is categorically different from a without-prejudice dismissal, which would preserve the right to refile. The choice of the with-prejudice designation here is notable and consistent with a party that has obtained what it sought — but the public record does not confirm this.
Claim-extinguishing dismissalPalo Alto Networks exits with permanent claim bar and no fee award
Palo Alto Networks secured the strongest possible procedural protection: a with-prejudice dismissal means Conexus cannot re-assert the same patent claims against them. However, the fee-neutral terms — each party bearing its own costs — suggest Palo Alto Networks did not pursue or obtain an exceptional case finding under 35 U.S.C. § 285, which would have required further litigation. The seven-day timeline made such a finding practically impossible in any event.
No § 285 fee shiftSeven-day dismissals signal rapid off-docket resolution in cybersecurity IP
Cases resolved within a week of filing — before service is typically completed — typically signal either a pre-litigation licensing agreement that was formalised after filing, a filing error requiring withdrawal, or a rapid commercial negotiation. For cybersecurity vendors facing injection-exploit patent assertions, the pattern suggests monitoring pre-suit demand letters carefully: substantive resolution may occur before any public court record emerges.
Pre-answer resolution patternFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | Conexus LLC | Company | Patent assertion entity — holder of US11736499B2 covering injection exploit detectionSearch in Eureka ↗ |
| Defendant | Palo Alto Networks, Inc. | Company | Palo Alto Networks, Inc. — global cybersecurity platform and network security vendorSearch in Eureka ↗ |
| Plaintiff counsel | Antranig N. Garibian | Attorney | Counsel for Conexus LLCSearch in Eureka ↗ |
| Plaintiff law firm | Garibian Law Offices, PC | Law Firm | Representing Conexus LLCSearch in Eureka ↗ |
| Presiding judge | Judge Jennifer L. Hall | Judge | Delaware District CourtSearch in Eureka ↗ |
Official order — verbatim text
The dismissal notice tracks the exact language of Rule 41(a)(1)(A)(i) and adds a with-prejudice designation alongside a mutual cost-bearing provision. The with-prejudice election is the operative legal fact: it converts a procedural withdrawal into a permanent bar on re-assertion of these claims against Palo Alto Networks. The fee-neutral cost allocation — each party bearing its own expenses — is consistent with either a negotiated exit or a plaintiff that recognised no fee-shifting exposure had yet accrued given the pre-answer posture.
US11736499B2 — Systems and Methods for Detecting Injection Exploits
US11736499B2, filed under application number US16/844,915, protects systems and methods for detecting injection exploits — a technically significant domain covering the automated identification of code or command injection attack vectors in software and network environments. Injection attacks, including SQL injection, OS command injection, and LDAP injection, remain among the most prevalent and damaging vulnerability classes in enterprise and cloud-native security contexts. The patent’s focus on detection methodology suggests claims directed at the analytical logic and system architecture for identifying such exploits, rather than purely at the exploit itself.
For the cybersecurity sector, this patent sits in a commercially crowded space: virtually every enterprise security vendor — from next-generation firewall providers to SIEM platforms and application security testing tools — incorporates some form of injection-attack detection. The breadth of potential defendant exposure is significant. Palo Alto Networks’ product portfolio, which includes Cortex XDR, Prisma Cloud, and NGFW threat prevention capabilities, would plausibly intersect with injection exploit detection claims, making this a commercially rational assertion target. The patent’s enforceability and claim scope against other vendors remains live.
Should your team run an FTO against US11736499B2?
Any organisation building or shipping products that detect, classify, or remediate injection-based attacks — including SQL injection, command injection, cross-site scripting variants, or API injection threats — should treat US11736499B2 as a patent requiring active FTO review. This is particularly true for vendors in the NGFW, WAF, SIEM, CSPM, and EDR segments. The dismissal of claims against Palo Alto Networks does not reduce third-party exposure; it simply closes one enforcement action while the patent remains fully in force.
PatSnap Eureka’s FTO Search Agent allows IP and R&D teams to map product feature sets against the independent and dependent claims of US11736499B2, identify prior art that may bear on validity, and benchmark claim scope against the file history. Eureka can also surface related continuation or divisional applications that may extend the claim family beyond the issued patent, helping your team assess the full perimeter of Conexus LLC’s injection-detection IP portfolio before any pre-suit demand arrives.
Run a freedom-to-operate analysis on US11736499B2 to assess your product’s exposure
Run FTO in Eureka →Similar cybersecurity patent infringement cases in D. Del.
Cases involving cybersecurity and network security patent assertions in the District of Delaware, including injection exploit detection and related threat-prevention technologies.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Systems and methods for detecting injection exploits-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedConexus LLC’s broader IP enforcement history
Conexus LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the cybersecurity patent assertion landscape
A seven-day with-prejudice dismissal against a tier-1 cybersecurity defendant raises questions that matter well beyond this single docket.
With-prejudice language is a meaningful signal, not boilerplate
Plaintiffs dismissing under Rule 41(a)(1)(A)(i) have the choice to dismiss with or without prejudice. Choosing with-prejudice — permanently barring refiling — typically indicates either a licensing deal has been reached or the plaintiff has a strategic reason to close the door entirely. IP teams at cybersecurity vendors should treat rapid with-prejudice dismissals as potential indicators of undisclosed licensing activity.
US11736499B2 remains enforceable against other cybersecurity defendants
The dismissal affects only Conexus’s claims against Palo Alto Networks. US11736499B2 is still in force and could be asserted against other vendors in the network security, SIEM, or application firewall space. Companies whose products involve injection attack detection — SQL, command, LDAP, or similar — should assess their exposure to this patent independently of this case outcome.
Delaware D. Del. remains the venue of choice for rapid-exit patent campaigns
The choice of Delaware for a filing resolved in 7 days is consistent with a forum-selection strategy that prizes speed and procedural flexibility over substantive adjudication. D. Del.’s predictable case management and plaintiff-friendly filing environment make it the preferred launch-and-settle venue for PAEs. Defendants should maintain standing D. Del. outside counsel relationships and early-response protocols even for complaints that may never be served.
Injection exploit detection patents are an emerging assertion vector in cybersecurity IP
US11736499B2 sits at the intersection of network security and software vulnerability detection — a technically dense but commercially broad claim space. As AI-driven security platforms proliferate, the detection of code injection and exploit patterns is increasingly embedded in core product functionality. Patent assertion entities holding IP in this domain may find a widening pool of potential defendants. Product and IP teams should map their injection-detection feature sets against the independent claims of US11736499B2.
Conexus v Palo — key questions answered
Conexus LLC filed a patent infringement complaint against Palo Alto Networks in the District of Delaware on July 17, 2025, asserting US11736499B2 covering systems and methods for detecting injection exploits. Seven days later, on July 24, 2025, Conexus voluntarily dismissed all claims with prejudice under Rule 41(a)(1)(A)(i), with each party bearing its own costs. No merits ruling was entered.
A dismissal with prejudice permanently bars Conexus from reasserting the same claims against Palo Alto Networks on US11736499B2. However, the patent itself remains in force and can still be enforced against other defendants. The dismissal is specific to Palo Alto Networks and has no bearing on Conexus’s ability to assert the patent against other cybersecurity vendors.
The public record does not disclose the reason. A seven-day with-prejudice dismissal is consistent with several scenarios: a pre-litigation licensing agreement formalised after filing, a rapid private settlement, or a strategic decision to withdraw. The mutual cost-bearing provision — rather than a fee award to either party — is consistent with a negotiated resolution, but this is speculative on the available record.
No. The dismissal only extinguishes Conexus’s claims against Palo Alto Networks specifically. US11736499B2 remains enforceable and other companies building products that detect injection exploits — including SQL injection, command injection, and similar attack classes — retain independent exposure. Any vendor whose products incorporate injection-attack detection logic should conduct an independent FTO review against this patent.
US11736499B2, filed as US application 16/844,915, covers systems and methods for detecting injection exploits. Injection exploits — including SQL injection, OS command injection, and LDAP injection — are among the most common and dangerous cyberattack vectors. The patent appears directed at the detection methodology and system architecture for identifying such attacks, making it potentially relevant to a wide range of enterprise security products including NGFWs, WAFs, SIEMs, and EDR platforms.
Monitor injection exploit patent risk before the next complaint lands
US11736499B2 is still in force. PatSnap Eureka lets your team run proactive FTO searches, track Conexus LLC’s portfolio activity, and receive alerts on new filings in the injection exploit detection space before a demand letter arrives.
PatSnap Eureka searches patents and litigation data to answer instantly.