PatchSiren

Palo Alto Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Palo Alto Networks CVE published 2026-07-14

CVE-2026-0272

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to onl [truncated]

LOW Palo Alto Networks CVE published 2026-07-14

CVE-2026-0266

CVE-2026-0266 is a cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software. This vulnerability allows a malicious authenticated administrator to store a JavaScript payload using the web interface. The affected products include PA-Series and VM-Series firewalls and Panorama (virtual and M-Series). However, Cloud NGFW and Prisma Access are not affected by this vulnerability. The Commo [truncated]

MEDIUM Palo Alto Networks CVE published 2026-07-09

CVE-2026-0278

CVE-2026-0278 is a MEDIUM severity vulnerability in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows. Multiple protection mechanism failures allow a local user to bypass DLP policy enforcement controls. The vulnerability has a CVSS score of 5.8. The Prisma Access Agent on macOS is not affected. Organizations should review their deployments and prioritize patching to prevent local u [truncated]

MEDIUM Palo Alto Networks CVE published 2026-07-09

CVE-2026-0277

CVE-2026-0277 is an improper certificate validation vulnerability in the Prisma Access Agent for iOS. This vulnerability allows an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android, and ChromeOS are not affected. Organizations should review their iOS deployments for the Prisma Access Agent and prioritize patching to pr [truncated]

LOW Palo Alto Networks CVE published 2026-07-09

CVE-2026-0276

A low-severity privilege escalation vulnerability was found in Palo Alto Networks Cortex XDR Broker VM. This vulnerability enables a locally authenticated user to perform actions as the root user. The CVE record was published on 2026-07-09T20:16:24.670Z and has not been modified since then. The NVD entry is currently limited, and further investigation is necessary to fully understand the issue and its pot [truncated]

LOW Palo Alto Networks CVE published 2026-07-09

CVE-2026-0275

CVE-2026-0275 is a local privilege escalation vulnerability in Palo Alto Networks Prisma Browser on macOS. An authenticated administrator with local filesystem access can perform actions with root privileges. This issue specifically affects Prisma Browser on macOS and does not impact other platforms. The vulnerability allows a locally authenticated administrator to escalate privileges to root, potentially [truncated]

MEDIUM Palo Alto Networks CVE published 2026-07-09

CVE-2026-0287

CVE-2026-0287 is a medium severity vulnerability in Palo Alto Networks PAN-OS software that allows an unauthenticated attacker to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Palo Alto Networks has released patches for affected version [truncated]

MEDIUM Palo Alto Networks CVE published 2026-07-09

CVE-2026-0286

CVE-2026-0286 is a command injection vulnerability in the management plane of Palo Alto Networks PAN-OS software. This vulnerability enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and [truncated]

MEDIUM Palo Alto Networks CVE published 2026-07-09

CVE-2026-0285

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. This issue impacts various versions of PAN-OS, including 10.2.0 to 10.2.16, 11.1.0 to 11.1.16, and 11.2.0 to 11.2.10, as well as specific hotfixes. The securi [truncated]

MEDIUM Palo Alto Networks CVE published 2026-07-09

CVE-2026-0283

CVE-2026-0283 is an authentication bypass vulnerability in Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software. This vulnerability allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. The affected products include various versions of PAN-OS software. Palo Alto Networks has provided a vendor advisory for mitigation.

LOW Palo Alto Networks CVE published 2026-07-09

CVE-2026-0282

A file deletion vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to best practice deployment guidelines. This issue is a [truncated]

LOW Palo Alto Networks CVE published 2026-07-09

CVE-2026-0281

CVE-2026-0281 is an information disclosure vulnerability in Palo Alto Networks PAN-OS software. An unauthenticated attacker with network access to the management web interface can obtain web session tokens, requiring a legitimate user to first click on a malicious link. The security risk is minimized by restricting access to the management web interface to only trusted internal IP addresses. The issue is [truncated]

LOW Palo Alto Networks CVE published 2026-07-09

CVE-2026-0280

CVE-2026-0280 is an IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS software. This vulnerability enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. The affected versions of PAN-OS software are 10.2.0 to 10.2.16, 11.1.0 to 11.1.16, and 11.2.0 to 11.2.10, and 12.1. [truncated]

LOW Palo Alto Networks CVE published 2026-07-09

CVE-2026-0279

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-09T19:16:58.717Z and has not been modified since then. The NVD entry is currently Analyzed. Multiple cross-site scripting vulnerabilities exist in Palo Alto Networks PAN-OS software, enabling malicious unauthenticated users to store or execute malicious JavaScript payload. The security risk is minim [truncated]

HIGH Palo Alto Networks CVE published 2026-07-08

CVE-2026-0288

CVE-2026-0288 is a HIGH severity vulnerability in Palo Alto Networks PAN-OS software. The vulnerability allows an unauthenticated attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted interna [truncated]

HIGH Palo Alto Networks CVE published 2026-06-10

CVE-2026-0274

CVE-2026-0274 is a HIGH severity vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM. An unauthenticated attacker can access and modify protected resources due to improper validation of credentials. The vulnerability has a CVSS score of 8.1.

MEDIUM Palo Alto Networks CVE published 2026-06-10

CVE-2026-0271

CVE-2026-0271 is a medium-severity privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices. This vulnerability enables a local user to execute code with elevated privileges. The vulnerability does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. The CVSS score for this vulnerability is 5.9.

MEDIUM Palo Alto Networks CVE published 2026-06-10

CVE-2026-0270

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

MEDIUM Palo Alto Networks CVE published 2026-06-10

CVE-2026-0269

CVE-2026-0269 is a memory corruption vulnerability in Palo Alto Networks PAN-OS software. An authenticated user can initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This vulnerability has a CVSS score of 4.6 and is classified as MEDIUM severity. Panorama, Cloud NGFW, and Prisma Access are not impacted by this [truncated]

MEDIUM Palo Alto Networks CVE published 2026-06-10

CVE-2026-0268

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This vulnerability does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

MEDIUM Palo Alto Networks CVE published 2026-06-10

CVE-2026-0267

CVE-2026-0267 is a MEDIUM-severity vulnerability in the Palo Alto Networks GlobalProtect app on macOS. The vulnerability enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After obtaining the passcode, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so. The vulnerabi [truncated]

Known exploited Palo Alto Networks CVE published 2026-05-29

CVE-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability. CISA added this issue to the Known Exploited Vulnerabilities catalog on 2026-05-29 with a remediation due date of 2026-06-01, indicating active exploitation in the wild. Federal agencies and organizations following CISA guidance must apply mitigations by the due date. The exact affected versions, root cause, and complete attack vec [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0243

CVE-2026-0243 is a denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices. An unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device can cause a system disruption by sending a specially crafted IPv6 packet. This vulnerability has a CVSS score of 4.9, indicating a medium severity level. The vulnerability exists due to improper handling of specially craft [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0259

CVE-2026-0259 is an arbitrary file read and delete vulnerability in Palo Alto Networks WildFire WF-500 and WF-500-B appliances. This vulnerability enables users to read sensitive information and delete arbitrary files. It affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The vulnerability has a CVSS score of 5 and a severity of MEDIUM. Security teams should assess [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0251

CVE-2026-0251 involves multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect app. This enables non-administrative users to execute arbitrary commands with administrative privileges on Windows, macOS, and Linux. The vulnerabilities allow a local user to escalate their privileges to NT AUTHORITY SYSTEM on Windows and root on macOS and Linux. The GlobalProtect app on iOS [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0250

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway. The GlobalProtect app on iOS is not affected.

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0249

CVE-2026-0249 is a MEDIUM severity vulnerability in Palo Alto Networks' GlobalProtect app. Multiple improper certificate validation vulnerabilities enable an attacker to intercept encrypted communications and potentially compromise the endpoint. This can allow a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0246

CVE-2026-0246 is a medium-severity vulnerability in Palo Alto Networks Prisma Access Agent, a locally authenticated non-administrative user can escalate privileges to root on macOS and Linux or NT AUTHORITY SYSTEM on Windows, allowing execution of arbitrary code and access to sensitive information normally restricted to privileged accounts. The Prisma Access Agent on iOS, Android, and Chrome OS are not af [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0245

CVE-2026-0245 is a multiple information disclosure vulnerability in Prisma Access Agent, allowing a local user to access sensitive configuration data and credentials. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected. This vulnerability affects Windows deployments of Prisma Access Agent. Administrators should r [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0244

CVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION. This vulnerability enables a man-in-the-middle (MitM) attacker to impersonate the controller. The CVSS score is 5.2, and the severity is MEDIUM. The affected versions include 6.3.1 to 6.3.6, 6.4.1 to 6.4.3, and 6.5.1 to 6.5.3. Specific builds like 6.3.6:b6, 6.3.6:b9, 6.4.3:b6, 6.4.3:b8, 6.5.3:b11, 6. [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0241

CVE-2026-0241 is an Incorrect Authorization vulnerability in Palo Alto Networks' Trust Protection Foundation. The vulnerability allows attackers to bypass access controls and perform unauthorized actions on restricted resources. The CVSS score is 5.1, indicating a medium severity level. The affected versions are 24.1.0 to 24.1.13, 24.3.0 to 24.3.6, 25.1.0 to 25.1.8, and 25.3.0 to 25.3.3. Security teams an [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0240

CVE-2026-0240 is an information disclosure vulnerability in Palo Alto Networks Trust Protection Foundation. An authenticated attacker can exploit this to obtain sensitive information from the server's vault, potentially allowing them to impersonate any user and modify configuration settings. The vulnerability affects various versions of Trust Protection Foundation, specifically versions 24.1.0 to 24.1.13, [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0239

CVE-2026-0239 is an information disclosure vulnerability in the Chronosphere Chronocollector. An unauthenticated attacker with network access can retrieve sensitive information. This vulnerability has a CVSS score of 4.9, indicating medium severity. The vulnerability allows an unauthenticated attacker with network access to the collector service to retrieve sensitive information. Users should assess the v [truncated]

LOW Palo Alto Networks CVE published 2026-05-13

CVE-2026-0238

The CVE-2026-0238 vulnerability is a low-severity issue in Palo Alto Networks Broker VM, allowing an authenticated administrator to inject arbitrary content into certain fields. This vulnerability has a CVSS score of 1.1 and is classified as CWE-20. It affects Broker VM versions from 30.0.0 to 30.0.24. System administrators and security teams managing Palo Alto Networks Broker VM should assess and apply t [truncated]

HIGH Palo Alto Networks CVE published 2026-05-13

CVE-2026-0236

A code injection vulnerability exists in Palo Alto Networks Prisma Browser on macOS. The vulnerability occurs because the browser fails to properly restrict access to its AppleScript interface. This allows a locally authenticated non-admin user to leverage the exposed Apple Event handler to send unauthorized commands to the browser. The vulnerability has a CVSS score of 7.3, indicating a high severity. Ad [truncated]

MEDIUM Palo Alto Networks CVE published 2026-05-13

CVE-2026-0235

A race condition vulnerability in Palo Alto Networks Prisma Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. This vulnerability, tracked as CVE-2026-0235, has a medium severity CVSS score of 5.8. The vulnerability allows an attacker to bypass certain access and data control policies, potentially leading to unauthorized access to sensitive data. Use [truncated]

HIGH Palo Alto Networks CVE published 2026-05-13

CVE-2026-0263

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. This vulnerability affects Palo Alto Networks PAN-OS software, while Panorama, Cloud NGFW, and Prisma Access are not impacted. The vulnerability has a [truncated]

HIGH Palo Alto Networks CVE published 2026-05-13

CVE-2026-0237

CVE-2026-0237 is an improper protection of alternate path vulnerability in Palo Alto Networks Prisma Browser on macOS. The vulnerability fails to properly restrict access to an internal automation bridge, allowing a locally authenticated non-admin user to send unauthorized commands to the browser, bypassing security controls. This could lead to potential security breaches if not addressed. Administrators [truncated]

CRITICAL Palo Alto Networks CVE published 2026-05-12

CVE-2026-0265

CVE-2026-0265 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS software. This issue enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced i [truncated]

CRITICAL Palo Alto Networks CVE published 2026-05-12

CVE-2026-0264

CVE-2026-0264 is a buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS Software. An unauthenticated attacker with network access can cause a denial of service (DoS) condition on all PAN-OS platforms except Cloud NGFW and Prisma Access. On PA-Series hardware only, the attacker may potentially execute arbitrary code by sending specially crafted network traffic [truncated]

HIGH Palo Alto Networks CVE published 2026-05-12

CVE-2026-0262

CVE-2026-0262 is a medium severity vulnerability in Palo Alto Networks PAN-OS software that allows an unauthenticated attacker to cause a denial of service (DoS) condition by sending specially crafted network traffic. The vulnerability has a CVSS score of 6.6 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-0262).

HIGH Palo Alto Networks CVE published 2026-05-12

CVE-2026-0261

CVE-2026-0261 is a medium-severity vulnerability (CVSS Score: 6.1) that affects Palo Alto Networks PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). The vulnerability allows an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user via the PAN-OS CLI or Web UI. The security risk is minimized when CLI access is restrict [truncated]

HIGH Palo Alto Networks CVE published 2026-05-12

CVE-2026-0258

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma Access are not impacted by these vulnerabilities.

MEDIUM Palo Alto Networks CVE published 2026-05-12

CVE-2026-0256

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Known exploited Palo Alto Networks CVE published 2026-05-06

CVE-2026-0300

CVE-2026-0300 is an out-of-bounds write vulnerability in Palo Alto Networks PAN-OS that CISA added to the Known Exploited Vulnerabilities catalog on 2026-05-06. The supplied CISA entry includes urgent mitigation guidance: apply vendor mitigations when available, restrict User-ID Authentication Portal access to trusted zones, and disable the portal if it is not required.

HIGH Palo Alto Networks CVE published 2026-04-13

CVE-2026-0234

CVE-2026-0234 is an improper verification of cryptographic signature vulnerability in Palo Alto Networks Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams. This vulnerability enables an unauthenticated user to access and modify protected resources. The CVSS score for this vulnerability is 7.2, indicating a high severity level. Security teams and administrators responsible for t [truncated]

LOW Palo Alto Networks CVE published 2026-04-13

CVE-2026-0233

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY SYSTEM privileges. The issue is related to improper certificate validation. Users of Palo Alto Networks Autonomous Digital Experience Manager on Windows should prioritize patching this vulne [truncated]

MEDIUM Palo Alto Networks CVE published 2026-04-13

CVE-2026-0232

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. The vulnerability has a CVSS score of 4 and is classified as MEDIUM severity. Organizations should review their deployments and apply mitigations or patches as recommend [truncated]

MEDIUM Palo Alto Networks CVE published 2025-06-10

CVE-2025-0133

CVE-2025-0133 was published on 2025-06-10 and updated on 2026-03-12. The supplied source corpus describes a reflected cross-site scripting (XSS) issue in GlobalProtect gateway and portal features that can execute malicious JavaScript in an authenticated Captive Portal user's browser after they click a specially crafted link. The main impact described is phishing and credential theft, especially where Clie [truncated]

Known exploited Palo Alto Networks CVE published 2025-02-20

CVE-2025-0111

CVE-2025-0111 is a Palo Alto Networks PAN-OS file read vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-20. KEV inclusion means the issue is considered actively exploited or of confirmed exploitation concern, so defenders should treat it as a high-priority remediation item even though the provided source corpus does not include a CVSS score or deeper technical detail.