| 7.2 | CVE-2026-0310
PAN-OS: Buffer Overflow Vulnerability via XML Processing | Cloud NGFW PAN-OS 12.2 PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access 12.1 Prisma Access 11.2 Prisma Access 10.2 | All on AWS*, All on Azure* < 12.2.3 < 12.1.4-h10, < 12.1.7-h5, < 12.1.10 < 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2 < 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2 < 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10 < 12.1.7-h5* < 11.2.7-h20* < 10.2.10-h40* | None on AWS*, None on Azure* >= 12.2.3 >= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10 >= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2 >= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2 >= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10 >= 12.1.7-h5* >= 11.2.7-h20* >= 10.2.10-h40* | 2026-09-09 | 2026-09-09 |
| 7.7 | PAN-SA-2026-0012
Chromium: Monthly Vulnerability Update (September 2026) | | | | 2026-09-09 | 2026-09-09 |
| 7.2 | PAN-SA-2026-0011
Chromium: Monthly Vulnerability Update (August 2026) | | | | 2026-08-12 | 2026-08-12 |
| 7.2 | CVE-2026-0288
PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access 11.2 Prisma Access 10.2 | None on AWS, None on Azure < 12.1.4-h8, < 12.1.7-h2, < 12.1.8 < 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13 < 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16 < 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8 < 11.2.7-h18* < 10.2.10-h39* | All on AWS, All on Azure unless you have been contacted by Palo Alto Networks >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16 >= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8 >= 11.2.7-h18* >= 10.2.10-h39* | 2026-07-08 | 2026-07-08 |
| 7.2 | PAN-SA-2026-0010
Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) | | | | 2026-07-08 | 2026-07-08 |
| 4.5 | CVE-2026-0283
PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h8, < 12.1.7-h2, < 12.1.8 < 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13 < 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16 < 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8 None | All >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16 >= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8 All | 2026-07-08 | 2026-07-08 |
| 5.8 | CVE-2026-0278
Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows | Prisma Access Agent Prisma Access Agent 0 | None on macOS < 26.2.1 on Windows | All on macOS >= 26.2.1 on Windows | 2026-07-08 | 2026-07-08 |
| 1.7 | CVE-2026-0280
PAN-OS: IPv6 Firewall Policy Bypass | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Panorama Prisma Access 11.2.0 Prisma Access 10.2.0 | None < 12.1.4-h8, < 12.1.7-h2, < 12.1.8 < 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h11, < 11.2.13 < 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16 < 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8 None < 11.2.7-h18* < 10.2.10-h39* | All >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16 >= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8 All >= 11.2.7-h18* >= 10.2.10-h39* | 2026-07-08 | 2026-07-08 |
| 8.1 | CVE-2026-0274
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration | Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1.0 Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1.0 | | | 2026-06-10 | 2026-06-10 |
| 5.9 | CVE-2026-0271
Prisma Access Agent: Local Privilege Escalation by Authorized Users | Prisma Access Agent Prisma Access Agent | None on macOS, None on Windows, None on iOS, None on Android, None on Chrome OS < 26.2.1 on Linux | All on macOS, All on Windows, All on iOS, All on Android, All on Chrome OS >= 26.2.1 on Linux | 2026-06-10 | 2026-06-10 |
| 8.4 | PAN-SA-2026-0008
Chromium: Monthly Vulnerability Update (June 2026) | | | | 2026-06-10 | 2026-06-10 |
| 7.2 | CVE-2026-0263
PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 None None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 All All | 2026-05-13 | 2026-05-28 |
| 7.2 | CVE-2026-0264
PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None on AWS, None on Azure < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All on AWS, All on Azure unless you have been contacted by Palo Alto Networks >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 7.2 | CVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 1.1 | CVE-2026-0238
Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields | | | | 2026-05-13 | 2026-05-13 |
| 5.9 | CVE-2026-0247
Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities | Prisma Access Agent (Endpoint DLP) | < 26.2.1 on macOS, < 26.2.1 on Windows | >= 26.2.1 on macOS, >= 26.2.1 on Windows | 2026-05-13 | 2026-05-13 |
| 9.3 | CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 (ETA: 05/28) >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-05 | 2026-05-28 |
| 7.2 | CVE-2026-0234
Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration | Cortex XSIAM Microsoft Teams Marketplace 1.5.0 Cortex XSOAR Microsoft Teams Marketplace 1.5.0 | | | 2026-04-08 | 2026-04-08 |
| i | PAN-SA-2026-0006
Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS | | | | 2026-04-08 | 2026-04-08 |
| 8.1 | PAN-SA-2026-0002
Chromium: Monthly Vulnerability Update (February 2026) | | | | 2026-02-11 | 2026-02-11 |
| 6.1 | CVE-2025-4231
PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None None < 11.0.3 < 10.2.8 All None | All All All >= 11.0.3 >= 10.2.8 None All | 2025-06-11 | 2025-06-11 |
| 7.6 | PAN-SA-2025-0009
Chromium: Monthly Vulnerability Update (May 2025) | | | | 2025-05-14 | 2025-05-15 |
| 1.1 | CVE-2025-0137
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.5 < 11.1.6-h14, < 11.1.8 < 10.2.13 < 10.1.14-h14 None | All >= 11.2.5 >= 11.1.6-h14, >= 11.1.8 >= 10.2.13 >= 10.1.14-h14 All | 2025-05-14 | 2025-07-11 |
| 2.7 | CVE-2025-0132
Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services | Cortex XDR Broker VM 26.0.0 | | | 2025-05-14 | 2025-05-14 |
| 4.4 | CVE-2025-0125
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.5 < 11.1.5 < 11.0.6 < 10.2.10-h19, < 10.2.11 < 10.1.14-h11 None | All >= 11.2.5 >= 11.1.5 >= 11.0.6 >= 10.2.10-h19, >= 10.2.11 >= 10.1.14-h11 All | 2025-04-09 | 2025-06-12 |