These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T03:16:46.097Z and has not been modified since then. This vulnerability, CVE-2026-0301, is an information disclosure issue in the URL Filtering feature of Palo Alto Networks PAN-OS software. It allows an unauthenticated user with network access to obtain sensitive information. The CVSS score of 1. [truncated]
CVE-2026-0296 Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected. This vulnerability affects Linux, macOS, and Windows deployments of the Glob [truncated]
A privilege escalation vulnerability in the Palo Alto Networks Prisma Access Agent app on Windows and macOS devices allows a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected. Defenders should assess exposure and prioritize remediation based on affected versions and device configurations. This vulnerability requires verificati [truncated]
A vulnerability in Palo Alto Networks Prisma Access Agent on Windows allows a local attacker with administrator privileges to bypass anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected. This vulnerability can have significant operational impacts, including unauthorized access to sensitiv [truncated]
A local administrator can bypass security inspection on Windows systems running Palo Alto Networks Prisma Access Agent, allowing them to inject and intercept arbitrary network traffic. This authentication bypass vulnerability is tracked as CVE-2026-0292 and has a CVSS score of 2.1, indicating a low severity. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
A local low-privileged user can delete system files and disable the Prisma Access Agent on Linux platforms due to an improper link resolution before file access vulnerability in the Palo Alto Networks Prisma Access Agent. This vulnerability allows for a limited scope of system file deletion and potential disruption of Prisma Access Agent functionality. Linux system administrators and security teams should [truncated]
A local attacker can view sensitive data due to an information disclosure vulnerability in Palo Alto Networks Prisma Browser's Account Protection feature. This vulnerability allows unauthorized access to sensitive information, potentially leading to further exploitation. Defenders and administrators should verify and apply patches to prevent local attackers from viewing sensitive data. The vulnerability i [truncated]
A security bypass vulnerability in Palo Alto Networks Prisma Browser's Account Protection feature allows users to bypass intended security controls. This issue has a CVSS score of 0.5 and is considered low severity. The vulnerability was published on August 13, 2026, and last modified on September 9, 2026. Defenders and security teams should assess their exposure and prioritize patching or applying workar [truncated]
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to onl [truncated]
CVE-2026-0266 is a cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software. This vulnerability allows a malicious authenticated administrator to store a JavaScript payload using the web interface. The affected products include PA-Series and VM-Series firewalls and Panorama (virtual and M-Series). However, Cloud NGFW and Prisma Access are not affected by this vulnerability. The Commo [truncated]
CVE-2026-0278 is a MEDIUM severity vulnerability in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows. Multiple protection mechanism failures allow a local user to bypass DLP policy enforcement controls. The vulnerability has a CVSS score of 5.8. The Prisma Access Agent on macOS is not affected. Organizations should review their deployments and prioritize patching to prevent local u [truncated]
CVE-2026-0277 is an improper certificate validation vulnerability in the Prisma Access Agent for iOS. This vulnerability allows an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android, and ChromeOS are not affected. Organizations should review their iOS deployments for the Prisma Access Agent and prioritize patching to pr [truncated]
A low-severity privilege escalation vulnerability was found in Palo Alto Networks Cortex XDR Broker VM. This vulnerability enables a locally authenticated user to perform actions as the root user. The CVE record was published on 2026-07-09T20:16:24.670Z and has not been modified since then. The NVD entry is currently limited, and further investigation is necessary to fully understand the issue and its pot [truncated]
CVE-2026-0275 is a local privilege escalation vulnerability in Palo Alto Networks Prisma Browser on macOS. An authenticated administrator with local filesystem access can perform actions with root privileges. This issue specifically affects Prisma Browser on macOS and does not impact other platforms. The vulnerability allows a locally authenticated administrator to escalate privileges to root, potentially [truncated]
CVE-2026-0287 is a medium severity vulnerability in Palo Alto Networks PAN-OS software that allows an unauthenticated attacker to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Palo Alto Networks has released patches for affected version [truncated]
CVE-2026-0286 is a command injection vulnerability in the management plane of Palo Alto Networks PAN-OS software. This vulnerability enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and [truncated]
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. This issue impacts various versions of PAN-OS, including 10.2.0 to 10.2.16, 11.1.0 to 11.1.16, and 11.2.0 to 11.2.10, as well as specific hotfixes. The securi [truncated]
CVE-2026-0283 is an authentication bypass vulnerability in Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software. This vulnerability allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. The affected products include various versions of PAN-OS software. Palo Alto Networks has provided a vendor advisory for mitigation.
A file deletion vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to best practice deployment guidelines. This issue is a [truncated]
CVE-2026-0281 is an information disclosure vulnerability in Palo Alto Networks PAN-OS software. An unauthenticated attacker with network access to the management web interface can obtain web session tokens, requiring a legitimate user to first click on a malicious link. The security risk is minimized by restricting access to the management web interface to only trusted internal IP addresses. The issue is [truncated]
CVE-2026-0280 is an IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS software. This vulnerability enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. The affected versions of PAN-OS software are 10.2.0 to 10.2.16, 11.1.0 to 11.1.16, and 11.2.0 to 11.2.10, and 12.1. [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-09T19:16:58.717Z and has not been modified since then. The NVD entry is currently Analyzed. Multiple cross-site scripting vulnerabilities exist in Palo Alto Networks PAN-OS software, enabling malicious unauthenticated users to store or execute malicious JavaScript payload. The security risk is minim [truncated]
CVE-2026-0288 is a HIGH severity vulnerability in Palo Alto Networks PAN-OS software. The vulnerability allows an unauthenticated attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted interna [truncated]
CVE-2026-0274 is a HIGH severity vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM. An unauthenticated attacker can access and modify protected resources due to improper validation of credentials. The vulnerability has a CVSS score of 8.1.
CVE-2026-0271 is a medium-severity privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices. This vulnerability enables a local user to execute code with elevated privileges. The vulnerability does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. The CVSS score for this vulnerability is 5.9.
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
CVE-2026-0269 is a memory corruption vulnerability in Palo Alto Networks PAN-OS software. An authenticated user can initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This vulnerability has a CVSS score of 4.6 and is classified as MEDIUM severity. Panorama, Cloud NGFW, and Prisma Access are not impacted by this [truncated]
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This vulnerability does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
CVE-2026-0267 is a MEDIUM-severity vulnerability in the Palo Alto Networks GlobalProtect app on macOS. The vulnerability enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After obtaining the passcode, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so. The vulnerabi [truncated]
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability debrief. The vulnerability, tracked as CVE-2026-0257, is a critical authentication bypass issue in Palo Alto Networks PAN-OS. This vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog, indicating known exploitation in the wild. Defenders of affected systems should assess exposure and prioritize remediation. The vulne [truncated]