Palo Alto Networks Security Advisories

1 - 25 of 135
VersionsAffectedUnaffected
4.3CVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux
Prisma Access Agent
Prisma Access Agent 24.0
None on macOS, None on Windows, None on iOS, None on Android, None on ChromeOS
< 26.3 on Linux
All on macOS, All on Windows, All on iOS, All on Android, All on ChromeOS
>= 26.3 on Linux
2026-09-092026-09-09
1.1CVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability
Checkov by Prisma Cloud 3.2.0
< 3.2.502
>= 3.2.502
2026-09-092026-09-09
2.4CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
Checkov by Prisma Cloud 3.2.0
< 3.2.532
>= 3.2.532
2026-09-092026-09-09
5.8CVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on macOS, None on iOS, None on Android, None on ChromeOS
< 26.2 on Windows
All on Linux, All on macOS, All on iOS, All on Android, All on ChromeOS
>= 26.2 on Windows
2026-09-092026-09-09
5.2CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.0
< 6.3.3-h15 on Linux, < 6.3.3-h14 (6.3.3-1121) on macOS, < 6.3.3-h14 (6.3.3-1121) on Windows, < 6.3.5 on iOS, < 6.3.5 on Android, < 6.3.5 on Chrome OS
All on Linux, < 6.2.8-h13 (6.2.8-1045) on macOS, < 6.2.8-h13 (6.2.8-1045) on Windows
< 6.0.15 on Linux, < 6.0.15 on macOS, < 6.0.15 on Windows, < 6.0.15 on iOS, < 6.0.15 on Android, < 6.0.15 on Chrome OS
>= 6.3.3-h15 on Linux (ETA: 08/28), >= 6.3.3-h14 (6.3.3-1121) on macOS, >= 6.3.3-h14 (6.3.3-1121) on Windows, >= 6.3.5 on iOS (ETA: 08/24), >= 6.3.5 on Android (ETA: 08/18), >= 6.3.5 on Chrome OS (ETA: 08/18)
None on Linux, >= 6.2.8-h13 (6.2.8-1045) on macOS, >= 6.2.8-h13 (6.2.8-1045) on Windows
>= 6.0.15 on Linux (ETA: 08/31), >= 6.0.15 on macOS (ETA: 08/31), >= 6.0.15 on Windows (ETA: 08/31), >= 6.0.15 on iOS (ETA: 08/31), >= 6.0.15 on Android (ETA: 08/31), >= 6.0.15 on Chrome OS (ETA: 08/31)
2026-08-122026-08-12
1.1CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux
Prisma Access Agent
Prisma Access Agent 0
None on macOS, None on Windows, None on iOS, None on Android, None on Chrome OS
< 26.2.2 on Linux
All on macOS, All on Windows, All on iOS, All on Android, All on Chrome OS
>= 26.2.2 on Linux
2026-08-122026-08-12
5.6CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
Prisma Access Agent
Prisma Access Agent 0
None on Linux, None on macOS, None on iOS, None on Android, None on Chrome OS
< 26.3 on Windows
All on Linux, All on macOS, All on iOS, All on Android, All on Chrome OS
>= 26.3 on Windows (ETA: 08/20)
2026-08-122026-08-12
7.2PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026)
Prisma Browser
< 148.18.4.217
>= 150.49.8.187
2026-08-122026-08-12
7.2PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Prisma Browser
< 149.10.3.53
>= 150.33.2.46
2026-07-082026-07-08
2.7CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.8
< 11.2.13
< 11.1.16
All
None
All
>= 12.1.8
>= 11.2.13
>= 11.1.16
None
All
2026-07-082026-07-08
4.8CVE-2026-0270 Cortex XSOAR: Path Traversal Vulnerability
Cortex XSOAR 8.13
Cortex XSOAR 8.12
Cortex XSOAR 8.11
Cortex XSOAR 8.10
Cortex XSOAR 6.14
Cortex XSOAR 6.13
Cortex XSOAR 6.12
< 8.13.0.11 on Linux
All
All
All
None
None
None
>= 8.13.0.11 on Linux
None
None
None
All
All
All
2026-06-102026-06-10
4.4CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect UWP App
None on Windows, Linux, iOS, Android, Chrome OS
< 6.3.3-h1 on macOS
< 6.2.8-h2 on macOS
None
All on Windows, Linux, iOS, Android, Chrome OS
>= 6.3.3-h1 on macOS
>= 6.2.8-h2 on macOS
All
2026-06-102026-06-10
4.8CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h5, < 12.1.7
< 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12
< 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15
< 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6
None
All
>= 12.1.4-h5, >= 12.1.7
>= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12
>= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15
>= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6
All
2026-05-132026-05-28
5CVE-2026-0259 WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)
WildFire WF-500 and WF-500-B 12.1.0
WildFire WF-500 and WF-500-B 11.2.0
WildFire WF-500 and WF-500-B 11.1.0
WildFire WF-500 and WF-500-B 10.2.0
< 12.1.4-h5, < 12.1.7
< 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12
< 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15
< 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6
>= 12.1.4-h5, >= 12.1.7
>= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12
>= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15
>= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6
2026-05-132026-05-28
5.9CVE-2026-0246 Prisma Access Agent: Local Privilege Escalation Vulnerability
Prisma Access Agent
Prisma Access Agent
None on Android, None on ChromeOS, None on iOS
< 26.2.1 on Linux, < 26.2.1 on macOS, < 26.2.1 on Windows
All on Android, All on ChromeOS, All on iOS
>= 26.2.1 on Linux, >= 26.2.1 on macOS, >= 26.2.1 on Windows
2026-05-132026-05-13
6.1PAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026)
Prisma Browser
< 145.7.9.76
>= 145.7.9.76
2026-03-112026-03-11
5.4CVE-2025-4615 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
None
< 11.2.8
< 11.1.4-h27, < 11.1.6-h21, < 11.1.10-h7
< 10.2.17
None
All
All
>= 11.2.8
>= 11.1.4-h27, >= 11.1.6-h21, >= 11.1.10-h7
>= 10.2.17
All
2025-10-082026-04-01
0.5CVE-2025-4234 Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials
Cortex XDR Microsoft 365 Defender Pack 4.6.0
< 4.6.5 on Windows
>= 4.6.5 on Windows
2025-09-102025-09-10
2CVE-2025-2181 Checkov by Prisma Cloud: Cleartext Exposure of Credentials
Checkov by Prisma Cloud 3.2.0
< 3.2.449
>= 3.2.449
2025-08-132025-08-13
1.1CVE-2025-2180 Checkov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code Execution
Checkov by Prisma Cloud 3.2.0
< 3.2.415
>= 3.2.415
2025-08-132025-08-13
4.5CVE-2025-2183 GlobalProtect App: Improper Certificate Validation Leads to Privilege Escalation
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on iOS, None on macOS
< 6.3.3-h2 (6.3.3-c676) on Windows, < 6.3.3 on Linux
< 6.2.8-h3 (6.2.8-c263) on Windows, All on Linux
All on Windows, All on Linux
< 6.0.12 on Windows, All on Linux
None
All on Android, All on iOS, All on macOS
>= 6.3.3-h2 (6.3.3-c676) on Windows*, >= 6.3.3 on Linux
>= 6.2.8-h3 (6.2.8-c263) on Windows*, None on Linux
None on Windows, None on Linux
>= 6.0.12 on Windows*, None on Linux
All
2025-08-132025-08-13
1CVE-2025-4228 Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
Cortex XDR Broker VM
< 27.0.26
>= 27.0.26
2025-06-112025-06-11
2CVE-2025-0124 PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
All
< 11.2.1
< 11.1.5
< 11.0.6
< 10.2.10
< 10.1.14-h11
None
None (ETA end of April)
>= 11.2.1
>= 11.1.5
>= 11.0.6
>= 10.2.10
>= 10.1.14-h11
All
2025-04-092025-04-09
1.9CVE-2025-0123 PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.6
< 11.1.6-h10, < 11.1.8
< 10.2.10-h21, < 10.2.15
< 10.1.14-h13
None
All
>= 11.2.6
>= 11.1.6-h10, >= 11.1.8
>= 10.2.10-h21, >= 10.2.15
>= 10.1.14-h13
All
2025-04-092025-07-11
4.3CVE-2025-0115 PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.3
< 11.1.4-h17, < 11.1.5
< 11.0.6
< 10.2.10-h18, < 10.2.11
< 10.1.14-h11
None
All
>= 11.2.3
>= 11.1.4-h17, >= 11.1.5
>= 11.0.6
>= 10.2.10-h18, >= 10.2.11
>= 10.1.14-h11
All
2025-03-122025-06-12
1 - 25 of 135 Download
© 2026 Palo Alto Networks, Inc. All rights reserved.