These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-0243 is a denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices. An unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device can cause a system disruption by sending a specially crafted IPv6 packet. This vulnerability has a CVSS score of 4.9, indicating a medium severity level. The vulnerability exists due to improper handling of specially craft [truncated]
CVE-2026-0259 is an arbitrary file read and delete vulnerability in Palo Alto Networks WildFire WF-500 and WF-500-B appliances. This vulnerability enables users to read sensitive information and delete arbitrary files. It affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The vulnerability has a CVSS score of 5 and a severity of MEDIUM. Security teams should assess [truncated]
CVE-2026-0251 involves multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect app. This enables non-administrative users to execute arbitrary commands with administrative privileges on Windows, macOS, and Linux. The vulnerabilities allow a local user to escalate their privileges to NT AUTHORITY SYSTEM on Windows and root on macOS and Linux. The GlobalProtect app on iOS [truncated]
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway. The GlobalProtect app on iOS is not affected.
CVE-2026-0249 is a MEDIUM severity vulnerability in Palo Alto Networks' GlobalProtect app. Multiple improper certificate validation vulnerabilities enable an attacker to intercept encrypted communications and potentially compromise the endpoint. This can allow a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the [truncated]
CVE-2026-0246 is a medium-severity vulnerability in Palo Alto Networks Prisma Access Agent, a locally authenticated non-administrative user can escalate privileges to root on macOS and Linux or NT AUTHORITY SYSTEM on Windows, allowing execution of arbitrary code and access to sensitive information normally restricted to privileged accounts. The Prisma Access Agent on iOS, Android, and Chrome OS are not af [truncated]
CVE-2026-0245 is a multiple information disclosure vulnerability in Prisma Access Agent, allowing a local user to access sensitive configuration data and credentials. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected. This vulnerability affects Windows deployments of Prisma Access Agent. Administrators should r [truncated]
CVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION. This vulnerability enables a man-in-the-middle (MitM) attacker to impersonate the controller. The CVSS score is 5.2, and the severity is MEDIUM. The affected versions include 6.3.1 to 6.3.6, 6.4.1 to 6.4.3, and 6.5.1 to 6.5.3. Specific builds like 6.3.6:b6, 6.3.6:b9, 6.4.3:b6, 6.4.3:b8, 6.5.3:b11, 6. [truncated]
CVE-2026-0241 is an Incorrect Authorization vulnerability in Palo Alto Networks' Trust Protection Foundation. The vulnerability allows attackers to bypass access controls and perform unauthorized actions on restricted resources. The CVSS score is 5.1, indicating a medium severity level. The affected versions are 24.1.0 to 24.1.13, 24.3.0 to 24.3.6, 25.1.0 to 25.1.8, and 25.3.0 to 25.3.3. Security teams an [truncated]
CVE-2026-0240 is an information disclosure vulnerability in Palo Alto Networks Trust Protection Foundation. An authenticated attacker can exploit this to obtain sensitive information from the server's vault, potentially allowing them to impersonate any user and modify configuration settings. The vulnerability affects various versions of Trust Protection Foundation, specifically versions 24.1.0 to 24.1.13, [truncated]
CVE-2026-0239 is an information disclosure vulnerability in the Chronosphere Chronocollector. An unauthenticated attacker with network access can retrieve sensitive information. This vulnerability has a CVSS score of 4.9, indicating medium severity. The vulnerability allows an unauthenticated attacker with network access to the collector service to retrieve sensitive information. Users should assess the v [truncated]
The CVE-2026-0238 vulnerability is a low-severity issue in Palo Alto Networks Broker VM, allowing an authenticated administrator to inject arbitrary content into certain fields. This vulnerability has a CVSS score of 1.1 and is classified as CWE-20. It affects Broker VM versions from 30.0.0 to 30.0.24. System administrators and security teams managing Palo Alto Networks Broker VM should assess and apply t [truncated]
A code injection vulnerability exists in Palo Alto Networks Prisma Browser on macOS. The vulnerability occurs because the browser fails to properly restrict access to its AppleScript interface. This allows a locally authenticated non-admin user to leverage the exposed Apple Event handler to send unauthorized commands to the browser. The vulnerability has a CVSS score of 7.3, indicating a high severity. Ad [truncated]
A race condition vulnerability in Palo Alto Networks Prisma Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. This vulnerability, tracked as CVE-2026-0235, has a medium severity CVSS score of 5.8. The vulnerability allows an attacker to bypass certain access and data control policies, potentially leading to unauthorized access to sensitive data. Use [truncated]
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. This vulnerability affects Palo Alto Networks PAN-OS software, while Panorama, Cloud NGFW, and Prisma Access are not impacted. The vulnerability has a [truncated]
CVE-2026-0237 is an improper protection of alternate path vulnerability in Palo Alto Networks Prisma Browser on macOS. The vulnerability fails to properly restrict access to an internal automation bridge, allowing a locally authenticated non-admin user to send unauthorized commands to the browser, bypassing security controls. This could lead to potential security breaches if not addressed. Administrators [truncated]
CVE-2026-0265 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS software. This issue enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced i [truncated]
CVE-2026-0264 is a buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS Software. An unauthenticated attacker with network access can cause a denial of service (DoS) condition on all PAN-OS platforms except Cloud NGFW and Prisma Access. On PA-Series hardware only, the attacker may potentially execute arbitrary code by sending specially crafted network traffic [truncated]
CVE-2026-0262 is a medium severity vulnerability in Palo Alto Networks PAN-OS software that allows an unauthenticated attacker to cause a denial of service (DoS) condition by sending specially crafted network traffic. The vulnerability has a CVSS score of 6.6 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-0262).
CVE-2026-0261 is a medium-severity vulnerability (CVSS Score: 6.1) that affects Palo Alto Networks PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). The vulnerability allows an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user via the PAN-OS CLI or Web UI. The security risk is minimized when CLI access is restrict [truncated]
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma Access are not impacted by these vulnerabilities.
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.
CVE-2026-0300 is an out-of-bounds write vulnerability in Palo Alto Networks PAN-OS that CISA added to the Known Exploited Vulnerabilities catalog on 2026-05-06. The supplied CISA entry includes urgent mitigation guidance: apply vendor mitigations when available, restrict User-ID Authentication Portal access to trusted zones, and disable the portal if it is not required.
CVE-2026-0234 is an improper verification of cryptographic signature vulnerability in Palo Alto Networks Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams. This vulnerability enables an unauthenticated user to access and modify protected resources. The CVSS score for this vulnerability is 7.2, indicating a high severity level. Security teams and administrators responsible for t [truncated]
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY SYSTEM privileges. The issue is related to improper certificate validation. Users of Palo Alto Networks Autonomous Digital Experience Manager on Windows should prioritize patching this vulne [truncated]
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. The vulnerability has a CVSS score of 4 and is classified as MEDIUM severity. Organizations should review their deployments and apply mitigations or patches as recommend [truncated]
CVE-2025-0133 was published on 2025-06-10 and updated on 2026-03-12. The supplied source corpus describes a reflected cross-site scripting (XSS) issue in GlobalProtect gateway and portal features that can execute malicious JavaScript in an authenticated Captive Portal user's browser after they click a specially crafted link. The main impact described is phishing and credential theft, especially where Clie [truncated]
CVE-2025-0111 is a Palo Alto Networks PAN-OS file read vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-20. KEV inclusion means the issue is considered actively exploited or of confirmed exploitation concern, so defenders should treat it as a high-priority remediation item even though the provided source corpus does not include a CVSS score or deeper technical detail.
CVE-2025-0108 is a Palo Alto Networks PAN-OS authentication bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-18. Because it is a KEV-listed issue, defenders should treat it as a high-priority exposure and follow vendor remediation guidance immediately. The supplied corpus does not include affected version ranges or patch details, so those should be verified in [truncated]
CVE-2024-3393 is a Palo Alto Networks PAN-OS issue described in the supplied record as a malicious DNS packet vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an active risk and prioritize mitigation. The supplied corpus does not include affected versions, impact details, or vendor remediation steps, so the safest approach is to use the [truncated]