Palo Alto Networks Security Advisories

1 - 25 of 248
VersionsAffectedUnaffected
2.4CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
Checkov by Prisma Cloud 3.2.0
< 3.2.532
>= 3.2.532
2026-09-092026-09-09
4.3CVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux
Prisma Access Agent
Prisma Access Agent 24.0
None on macOS, None on Windows, None on iOS, None on Android, None on ChromeOS
< 26.3 on Linux
All on macOS, All on Windows, All on iOS, All on Android, All on ChromeOS
>= 26.3 on Linux
2026-09-092026-09-09
1.1CVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability
Checkov by Prisma Cloud 3.2.0
< 3.2.502
>= 3.2.502
2026-09-092026-09-09
5.8CVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on macOS, None on iOS, None on Android, None on ChromeOS
< 26.2 on Windows
All on Linux, All on macOS, All on iOS, All on Android, All on ChromeOS
>= 26.2 on Windows
2026-09-092026-09-09
4CVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
Cloud NGFW
PAN-OS 12.2
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.2.3
< 12.1.4-h10, < 12.1.7-h5, < 12.1.10
< 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2
< 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2
< 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10
None
All
>= 12.2.3
>= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10
>= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
>= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2
>= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10
All
2026-09-092026-09-09
7.2CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing
Cloud NGFW
PAN-OS 12.2
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 12.1
Prisma Access 11.2
Prisma Access 10.2
All on AWS*, All on Azure*
< 12.2.3
< 12.1.4-h10, < 12.1.7-h5, < 12.1.10
< 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2
< 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2
< 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10
< 12.1.7-h5*
< 11.2.7-h20*
< 10.2.10-h40*
None on AWS*, None on Azure*
>= 12.2.3
>= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10
>= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
>= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2
>= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10
>= 12.1.7-h5*
>= 11.2.7-h20*
>= 10.2.10-h40*
2026-09-092026-09-09
7.7PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026)
Prisma Browser
< 151.26.5.170
>= 152.8.4.76
2026-09-092026-09-09
5.9CVE-2026-0307 GlobalProtect App: Local Privilege Escalation Vulnerabilities
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.0
None on iOS, None on Android, None on ChromeOS
< 6.3.3-h15 on Linux (ETA: 09/17), < 6.3.3-h15 on macOS (ETA: 09/28), < 6.3.3-h15 on Windows (ETA: 09/28)
< 6.2.8-h14 on macOS, < 6.2.8-h14 on Windows
< 6.0.15 on Linux (ETA: 09/28), < 6.0.15 on macOS (ETA: 09/28), < 6.0.15 on Windows (ETA: 10/29)
All on iOS, All on Android, All on ChromeOS
>= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h15 on macOS (ETA: 09/28), >= 6.3.3-h15 on Windows (ETA: 09/28)
>= 6.2.8-h14 on macOS, >= 6.2.8-h14 on Windows
>= 6.0.15 on Linux (ETA: 09/28), >= 6.0.15 on macOS (ETA: 09/28), >= 6.0.15 on Windows (ETA: 10/29)
2026-09-092026-09-09
1.1CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Cloud NGFW
PAN-OS 12.2
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
Prisma Access
None
None
< 12.1.10
< 11.2.13-h2
< 11.1.16-h2
None
All
All
>= 12.1.10
>= 11.2.13-h2
>= 11.1.16-h2
All
2026-09-092026-09-09
1.7CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 12.1
Prisma Access 11.2
Prisma Access 10.2
All on AWS*, All on Azure*
None
None
< 11.1.16-h1
< 10.2.8
None
None
< 10.2.10
None on AWS*, None on Azure*
All
All
>= 11.1.16-h1
>= 10.2.8
All
All
>= 10.2.10
2026-08-122026-08-12
4.1CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.0
None on Linux, None on Windows, None on iOS, None on Android, None on Chrome OS
< 6.3.3-h14 (6.3.3-1121) on macOS
< 6.2.8-h13 (6.2.8-1045) on macOS
< 6.0.15 on macOS
All on Linux, All on Windows, All on iOS, All on Android, All on Chrome OS
>= 6.3.3-h14 (6.3.3-1121) on macOS
>= 6.2.8-h13 (6.2.8-1045) on macOS
>= 6.0.15 on macOS (ETA: 08/31)
2026-08-122026-08-12
2.1CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on macOS, None on iOS, None on Android, None on Chrome OS
< 26.3 on Windows
All on Linux, All on macOS, All on iOS, All on Android, All on Chrome OS
>= 26.3 on Windows (ETA: 08/20)
2026-08-122026-08-12
6CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on iOS, None on Android, None on Chrome OS
< 26.3 on Windows, < 26.3 on macOS
All on Linux, All on iOS, All on Android, All on Chrome OS
>= 26.3 on Windows (ETA: 08/20), >= 26.3 on macOS (ETA: 08/20)
2026-08-122026-08-12
1.1CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux
Prisma Access Agent
Prisma Access Agent 0
None on macOS, None on Windows, None on iOS, None on Android, None on Chrome OS
< 26.2.2 on Linux
All on macOS, All on Windows, All on iOS, All on Android, All on Chrome OS
>= 26.2.2 on Linux
2026-08-122026-08-12
5.6CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on macOS, None on iOS, None on Android, None on Chrome OS
< 26.3 on Windows
All on Linux, All on macOS, All on iOS, All on Android, All on Chrome OS
>= 26.3 on Windows (ETA: 08/20)
2026-08-122026-08-12
7.2PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026)
Prisma Browser
< 148.18.4.217
>= 150.49.8.187
2026-08-122026-08-12
6.6CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 11.2.0
Prisma Access 10.2.0
All on AWS, All on Azure
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
< 11.2.7-h18*
< 10.2.10-h39*
None on AWS, None on Azure
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
>= 11.2.7-h18*
>= 10.2.10-h39*
2026-07-082026-07-08
5.7CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on Windows, None on macOS, None on Android, None on ChromeOS
< 26.2.1 on iOS
All on Linux, All on Windows, All on macOS, All on Android, All on ChromeOS
>= 26.2.1 on iOS
2026-07-082026-07-08
7.2CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 11.2
Prisma Access 10.2
None on AWS, None on Azure
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
< 11.2.7-h18*
< 10.2.10-h39*
All on AWS, All on Azure unless you have been contacted by Palo Alto Networks
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
>= 11.2.7-h18*
>= 10.2.10-h39*
2026-07-082026-07-08
1.3CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 12.1
Prisma Access 11.2
Prisma Access 10.2
None
< 12.1.8
< 11.2.13
< 11.1.16
All
< 12.1.8*
All*
All*
All
>= 12.1.8
>= 11.2.13
>= 11.1.16
None
>= 12.1.8*
None*
None*
2026-07-082026-07-08
5.8CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
Prisma Access Agent
Prisma Access Agent 0
None on macOS
< 26.2.1 on Windows
All on macOS
>= 26.2.1 on Windows
2026-07-082026-07-08
4.5CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
None
All
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
All
2026-07-082026-07-08
6CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h11, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
None
All
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
All
2026-07-082026-07-08
1.7CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Panorama
Prisma Access 11.2.0
Prisma Access 10.2.0
None
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h11, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
None
< 11.2.7-h18*
< 10.2.10-h39*
All
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
All
>= 11.2.7-h18*
>= 10.2.10-h39*
2026-07-082026-07-08
2.1CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.8
< 11.2.13
< 11.1.16
All
None
All
>= 12.1.8
>= 11.2.13
>= 11.1.16
None
All
2026-07-082026-07-08
1 - 25 of 248 Download
© 2026 Palo Alto Networks, Inc. All rights reserved.