| 7.7 | CVE-2026-0227
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access 11.2 Prisma Access 10.2 | None < 12.1.3-h3, < 12.1.4 < 11.2.4-h15, < 11.2.7-h8, < 11.2.10-h2 < 11.1.4-h27, < 11.1.6-h23, < 11.1.10-h9, < 11.1.13 < 10.2.7-h32, < 10.2.10-h31, < 10.2.13-h18, < 10.2.16-h6, < 10.2.18-h1 < 10.1.14-h20 < 11.2.7-h8* < 10.2.4-h43*, < 10.2.10-h29* | All >= 12.1.3-h3, >= 12.1.4 >= 11.2.4-h15, >= 11.2.7-h8, >= 11.2.10-h2 >= 11.1.4-h27, >= 11.1.6-h23, >= 11.1.10-h9, >= 11.1.13 >= 10.2.7-h32, >= 10.2.10-h31, >= 10.2.13-h18, >= 10.2.16-h6, >= 10.2.18-h1 >= 10.1.14-h20 >= 11.2.7-h8* >= 10.2.4-h43*, >= 10.2.10-h29* | 2026-01-14 | 2026-02-09 |
| 6.1 | CVE-2025-4231
PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None None < 11.0.3 < 10.2.8 All None | All All All >= 11.0.3 >= 10.2.8 None All | 2025-06-11 | 2025-06-11 |
| 2 | CVE-2025-0133
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | All < 11.2.4-h9, < 11.2.7 < 11.1.6-h14, < 11.1.10-h1 < 10.2.16-h1 All All | None (See Mitigations and Workarounds) >= 11.2.4-h9, >= 11.2.7 >= 11.1.6-h14, >= 11.1.10-h1 >= 10.2.16-h1 None None (See Mitigations and Workarounds) | 2025-05-14 | 2025-07-09 |
| i | PAN-SA-2025-0005
GlobalProtect Clientless VPN: Clientless VPN Misconfiguration Allows Cross-Site Attacks | Cloud NGFW PAN-OS Prisma Access | | | 2025-02-12 | 2025-02-12 |
| 6 | CVE-2023-48795
Impact of Terrapin SSH Attack | PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 9.1 PAN-OS 9.0 | None < 11.2.8 < 11.1.8 All < 10.2.14 All All All | All >= 11.2.8 >= 11.1.8 ¹ None ² >= 10.2.14 ¹ None None None | 2024-01-09 | 2026-03-10 |
| 3 | CVE-2020-2035
PAN-OS: URL filtering policy is not enforced on TLS handshakes for decrypted HTTPS sessions | PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 | All without CTD inspection enabled All All All All | None with CTD inspection enabled None None None None | 2020-08-12 | 2021-07-20 |