Palo Alto Networks Security Advisories

1 - 25 of 187
VersionsAffectedUnaffected
1.1CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Cloud NGFW
PAN-OS 12.2
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
Prisma Access
None
None
< 12.1.10
< 11.2.13-h2
< 11.1.16-h2
None
All
All
>= 12.1.10
>= 11.2.13-h2
>= 11.1.16-h2
All
2026-09-092026-09-09
4CVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
Cloud NGFW
PAN-OS 12.2
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.2.3
< 12.1.4-h10, < 12.1.7-h5, < 12.1.10
< 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2
< 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2
< 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10
None
All
>= 12.2.3
>= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10
>= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
>= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2
>= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10
All
2026-09-092026-09-09
7.2CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing
Cloud NGFW
PAN-OS 12.2
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 12.1
Prisma Access 11.2
Prisma Access 10.2
All on AWS*, All on Azure*
< 12.2.3
< 12.1.4-h10, < 12.1.7-h5, < 12.1.10
< 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2
< 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2
< 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10
< 12.1.7-h5*
< 11.2.7-h20*
< 10.2.10-h40*
None on AWS*, None on Azure*
>= 12.2.3
>= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10
>= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
>= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2
>= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10
>= 12.1.7-h5*
>= 11.2.7-h20*
>= 10.2.10-h40*
2026-09-092026-09-09
7.2PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026)
Prisma Browser
< 148.18.4.217
>= 150.49.8.187
2026-08-122026-08-12
1.7CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 12.1
Prisma Access 11.2
Prisma Access 10.2
All on AWS*, All on Azure*
None
None
< 11.1.16-h1
< 10.2.8
None
None
< 10.2.10
None on AWS*, None on Azure*
All
All
>= 11.1.16-h1
>= 10.2.8
All
All
>= 10.2.10
2026-08-122026-08-12
7.2PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Prisma Browser
< 149.10.3.53
>= 150.33.2.46
2026-07-082026-07-08
4.5CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
None
All
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
All
2026-07-082026-07-08
2.1CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.8
< 11.2.13
< 11.1.16
All
None
All
>= 12.1.8
>= 11.2.13
>= 11.1.16
None
All
2026-07-082026-07-08
1.3CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access 12.1
Prisma Access 11.2
Prisma Access 10.2
None
< 12.1.8
< 11.2.13
< 11.1.16
All
< 12.1.8*
All*
All*
All
>= 12.1.8
>= 11.2.13
>= 11.1.16
None
>= 12.1.8*
None*
None*
2026-07-082026-07-08
2.7CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.8
< 11.2.13
< 11.1.16
All
None
All
>= 12.1.8
>= 11.2.13
>= 11.1.16
None
All
2026-07-082026-07-08
4.7CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h12, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
None
All
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
All
2026-07-082026-07-08
4.7CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h8, < 12.1.7-h2, < 12.1.8
< 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h11, < 11.2.13
< 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
< 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8
None
All
>= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
>= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13
>= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
>= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
All
2026-07-082026-07-08
6.1CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h7, < 12.1.7
< 11.2.4-h18, < 11.2.7-h16, < 11.2.10-h9, < 11.2.12
< 11.1.4-h34, < 11.1.6-h33, < 11.1.7-h7, < 11.1.10-h27, < 11.1.13-h7, < 11.1.15
< 10.2.7-h35, < 10.2.10-h37, < 10.2.13-h22, < 10.2.16-h8, < 10.2.18-h7
None
All
>= 12.1.4-h7, >= 12.1.7
>= 11.2.4-h18, >= 11.2.7-h16, >= 11.2.10-h9, >= 11.2.12
>= 11.1.4-h34, >= 11.1.6-h33, >= 11.1.7-h7, >= 11.1.10-h27, >= 11.1.13-h7, >= 11.1.15
>= 10.2.7-h35, >= 10.2.10-h37, >= 10.2.13-h22, >= 10.2.16-h8, >= 10.2.18-h7
All
2026-06-102026-06-11
1.1CVE-2026-0266 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.5
< 11.2.11
< 11.1.14
All
None
All
>= 12.1.5
>= 11.2.11
>= 11.1.14
None
All
2026-06-102026-06-10
7.2CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h5, < 12.1.7
< 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12
< 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15
< 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6
None
All
>= 12.1.4-h5, >= 12.1.7
>= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12
>= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15
>= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6
All
2026-05-132026-05-28
6.1CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h5, < 12.1.7
< 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12
< 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15
< 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6
None
All
>= 12.1.4-h5, >= 12.1.7
>= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12
>= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15
>= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6
All
2026-05-132026-05-28
6.1PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
Prisma Browser
< 146.10.7.154
>= 148.6.3.96
2026-05-132026-05-13
4.4CVE-2026-0256 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
< 12.1.4-h5, < 12.1.7
< 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12
< 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15
< 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6
None
All
>= 12.1.4-h5, >= 12.1.7
>= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12
>= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15
>= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6
All
2026-05-132026-05-28
1.1CVE-2025-4614 PAN-OS: Session Token Disclosure Vulnerability
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
None
< 11.2.8
< 11.1.6-h21
< 10.2.17
None
All
All
>= 11.2.8
>= 11.1.6-h21
>= 10.2.17
All
2025-10-082025-10-08
5.4CVE-2025-4615 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
Prisma Access
None
None
< 11.2.8
< 11.1.4-h27, < 11.1.6-h21, < 11.1.10-h7
< 10.2.17
None
All
All
>= 11.2.8
>= 11.1.4-h27, >= 11.1.6-h21, >= 11.1.10-h7
>= 10.2.17
All
2025-10-082026-04-01
3.3CVE-2025-2182 PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)
Cloud NGFW
PAN-OS
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None on devices other than PA-7500
< 11.2.8 on PA-7500
< 11.1.10 on PA-7500
None on PA-7500
None on PA-7500
None
All
All on devices other than PA-7500
>= 11.2.8 on PA-7500
>= 11.1.10 on PA-7500
All on PA-7500
All on PA-7500
All
2025-08-132025-08-13
4.3CVE-2025-2179 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App
GlobalProtect App
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on Chrome OS, None on iOS, None on Windows, None on macOS
< 6.2.9 on Linux
All on Linux
All on Linux
None
All on Android, All on Chrome OS, All on iOS, All on Windows, All on macOS
>= 6.2.9 on Linux
None on Linux
None on Linux
All
2025-07-282025-07-28
6.1CVE-2025-4231 PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None
None
< 11.0.3
< 10.2.8
All
None
All
All
All
>= 11.0.3
>= 10.2.8
None
All
2025-06-112025-06-11
2.3CVE-2025-4229 PAN-OS: Traffic Information Disclosure Vulnerability
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.7
< 11.1.10
< 10.2.16-h1, < 10.2.17
< 10.1.14-h16
None
All
>= 11.2.7
>= 11.1.10
>= 10.2.16-h1, >= 10.2.17
>= 10.1.14-h16
All
2025-06-112025-06-30
1.1CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.6-h14, < 11.1.8
< 10.2.13
< 10.1.14-h14
None
All
>= 11.2.5
>= 11.1.6-h14, >= 11.1.8
>= 10.2.13
>= 10.1.14-h14
All
2025-05-142025-07-11
1 - 25 of 187 Download
© 2026 Palo Alto Networks, Inc. All rights reserved.