| 4.4 | CVE-2026-0256
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 7.8 | CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access 11.2.0 Prisma Access 10.2.0 | None < 12.1.4-h6, < 12.1.7 < 11.2.4-h17, < 11.2.7-h14, < 11.2.10-h7, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 < 11.2.7-h13* < 10.2.10-h36* | All >= 12.1.4-h6, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h14, >= 11.2.10-h7, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 >= 11.2.7-h13* >= 10.2.10-h36* | 2026-05-13 | 2026-05-29 |
| 4.8 | CVE-2026-0258
PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 6.1 | CVE-2026-0261
PAN-OS: Authenticated Admin Command Injection Vulnerability | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 6.6 | CVE-2026-0262
PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None on Azure/AWS < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None* | All on Azure/AWS >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All* | 2026-05-13 | 2026-05-28 |
| 7.2 | CVE-2026-0263
PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 None None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 All All | 2026-05-13 | 2026-05-28 |
| 7.2 | CVE-2026-0264
PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None on AWS, None on Azure < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All on AWS, All on Azure unless you have been contacted by Palo Alto Networks >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 7.2 | CVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 9.3 | CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 (ETA: 05/28) >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-05 | 2026-05-28 |
| 7.7 | CVE-2026-0227
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access 11.2 Prisma Access 10.2 | None < 12.1.3-h3, < 12.1.4 < 11.2.4-h15, < 11.2.7-h8, < 11.2.10-h2 < 11.1.4-h27, < 11.1.6-h23, < 11.1.10-h9, < 11.1.13 < 10.2.7-h32, < 10.2.10-h31, < 10.2.13-h18, < 10.2.16-h6, < 10.2.18-h1 < 10.1.14-h20 < 11.2.7-h8* < 10.2.4-h43*, < 10.2.10-h29* | All >= 12.1.3-h3, >= 12.1.4 >= 11.2.4-h15, >= 11.2.7-h8, >= 11.2.10-h2 >= 11.1.4-h27, >= 11.1.6-h23, >= 11.1.10-h9, >= 11.1.13 >= 10.2.7-h32, >= 10.2.10-h31, >= 10.2.13-h18, >= 10.2.16-h6, >= 10.2.18-h1 >= 10.1.14-h20 >= 11.2.7-h8* >= 10.2.4-h43*, >= 10.2.10-h29* | 2026-01-14 | 2026-02-09 |