{"document":{"category":"csaf_vex","csaf_version":"2.1","notes":[{"category":"summary","text":"Palo Alto Networks PSIRT provided VEX document. This document is autogenerated.","title":"Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS"}],"publisher":{"category":"vendor","name":"Palo Alto Networks","namespace":"https://security.paloaltonetworks.com"},"title":"Palo Alto Networks PSIRT provided VEX document: PAN-SA-2026-0006","distribution":{"text":"Copyright © 2024 Palo Alto Networks. All rights reserved.","tlp":{"label":"CLEAR","url":"https://www.first.org/tlp/"}},"tracking":{"current_release_date":"2026-09-18T16:54:37.007Z","generator":{"date":"2026-09-18T16:54:37.007Z","engine":{"name":"Vulnogram","version":"0.1.0-dev"}},"id":"PAN-SA-2026-0006","initial_release_date":"2026-04-08T16:00:00.000Z","revision_history":[{"number":"1","date":"2026-04-08T09:00:00.000Z","summary":"Initial Publication"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"name":"Palo Alto Networks","category":"vendor","branches":[{"name":"PAN-OS","category":"product_name","branches":[{"category":"product_version","name":"PAN-OS All","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-1"}}]}]}]},"vulnerabilities":[{"cve":"CVE-2023-2176","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use RDMA."}],"references":[{"category":"external","summary":"NVD - CVE-2023-2176","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2176"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use RDMA."}]},{"cve":"CVE-2023-5633","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS as the prerequisite conditions needed to be vulnerable do not exists in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2023-5633","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5633"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS as the prerequisite conditions needed to be vulnerable do not exists in PAN-OS."}]},{"cve":"CVE-2023-28464","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use the Bluetooth subsystem."}],"references":[{"category":"external","summary":"NVD - CVE-2023-28464","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28464"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use the Bluetooth subsystem."}]},{"cve":"CVE-2024-0646","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use the function splice() with a ktls socket as the destination."}],"references":[{"category":"external","summary":"NVD - CVE-2024-0646","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0646"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use the function splice() with a ktls socket as the destination."}]},{"cve":"CVE-2024-36971","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use the vulnerable function __dst_negative_advice()."}],"references":[{"category":"external","summary":"NVD - CVE-2024-36971","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36971"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use the vulnerable function __dst_negative_advice()."}]},{"cve":"CVE-2024-36886","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use the vulnerable function  tipc_buf_append()."}],"references":[{"category":"external","summary":"NVD - CVE-2024-36886","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36886"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use the vulnerable function  tipc_buf_append()."}]},{"cve":"CVE-2025-57052","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable cjson library."}],"references":[{"category":"external","summary":"NVD - CVE-2025-57052","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57052"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable cjson library."}]},{"cve":"CVE-2026-27654","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use the vulnerable DAV module."}],"references":[{"category":"external","summary":"NVD - CVE-2026-27654","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27654"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use the vulnerable DAV module."}]},{"cve":"CVE-2026-49975","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected. The WebUI, GlobalProtect Portal, and Gateway interfaces do not use HTTP/2."}],"references":[{"category":"external","summary":"NVD - CVE-2026-49975","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49975"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected. The WebUI, GlobalProtect Portal, and Gateway interfaces do not use HTTP/2."}]},{"cve":"CVE-2026-55200","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have libssh2."}],"references":[{"category":"external","summary":"NVD - CVE-2026-55200","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55200"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have libssh2."}]},{"cve":"CVE-2023-51767","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected because of our underlying system architecture and security controls."}],"references":[{"category":"external","summary":"NVD - CVE-2023-51767","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-51767"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected because of our underlying system architecture and security controls."}]},{"cve":"CVE-2023-38408","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have SSH-agent."}],"references":[{"category":"external","summary":"NVD - CVE-2023-38408","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38408"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have SSH-agent."}]},{"cve":"CVE-2019-16905","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS has custom OpenSSH packages that do not support XMSS."}],"references":[{"category":"external","summary":"NVD - CVE-2019-16905","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16905"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS has custom OpenSSH packages that do not support XMSS."}]},{"cve":"CVE-2026-34197","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not use Apache ActiveMQ Broker and Apache ActiveMQ."}],"references":[{"category":"external","summary":"NVD - CVE-2026-34197","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34197"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not use Apache ActiveMQ Broker and Apache ActiveMQ."}]},{"cve":"CVE-2026-21265","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have Microsoft Secure Boot certificates."}],"references":[{"category":"external","summary":"NVD - CVE-2026-21265","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21265"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have Microsoft Secure Boot certificates."}]},{"cve":"CVE-2026-35386","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2026-35386","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35386"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2026-35387","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2026-35387","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35387"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2026-35388","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2026-35388","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35388"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2026-35414","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2026-35414","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35414"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2026-59995","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2026-59995","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2026-59996","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2026-59996","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2026-59997","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have the vulnerable OpenSSH internal-sftp subsystem."}],"references":[{"category":"external","summary":"NVD - CVE-2026-59997","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have the vulnerable OpenSSH internal-sftp subsystem."}]},{"cve":"CVE-2026-59998","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have GSSAPI authentication."}],"references":[{"category":"external","summary":"NVD - CVE-2026-59998","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have GSSAPI authentication."}]},{"cve":"CVE-2026-59999","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not enable SSH TCP forwarding or tunneling."}],"references":[{"category":"external","summary":"NVD - CVE-2026-59999","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not enable SSH TCP forwarding or tunneling."}]},{"cve":"CVE-2026-60000","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have GSSAPI authentication."}],"references":[{"category":"external","summary":"NVD - CVE-2026-60000","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have GSSAPI authentication."}]},{"cve":"CVE-2019-0217","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as the prerequisite conditions needed to be vulnerable do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2019-0217","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0217"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as the prerequisite conditions needed to be vulnerable do not exist in PAN-OS."}]},{"cve":"CVE-2019-10092","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"AN-OS is not affected as PAN-OS does not have mod_proxy."}],"references":[{"category":"external","summary":"NVD - CVE-2019-10092","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10092"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"AN-OS is not affected as PAN-OS does not have mod_proxy."}]},{"cve":"CVE-2019-10098","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have mod_proxy."}],"references":[{"category":"external","summary":"NVD - CVE-2019-10098","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10098"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have mod_proxy."}]},{"cve":"CVE-2020-14040","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"AN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}],"references":[{"category":"external","summary":"NVD - CVE-2020-14040","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-14040"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"AN-OS is not affected as the necessary preconditions required to exploit this vulnerability do not exist in PAN-OS."}]},{"cve":"CVE-2020-28463","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS uses Red Hat Enterprise Linux packages where this vulnerability does not impact the system."}],"references":[{"category":"external","summary":"NVD - CVE-2020-28463","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28463"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS uses Red Hat Enterprise Linux packages where this vulnerability does not impact the system."}]},{"cve":"CVE-2020-29652","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package."}],"references":[{"category":"external","summary":"NVD - CVE-2020-29652","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-29652"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package."}]},{"cve":"CVE-2020-9283","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"AN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package."}],"references":[{"category":"external","summary":"NVD - CVE-2020-9283","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9283"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"AN-OS is not affected as PAN-OS does not have the golang.org/x/crypto/ssh package."}]},{"cve":"CVE-2021-33193","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have mod_proxy."}],"references":[{"category":"external","summary":"NVD - CVE-2021-33193","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33193"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have mod_proxy."}]},{"cve":"CVE-2021-36160","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi."}],"references":[{"category":"external","summary":"NVD - CVE-2021-36160","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36160"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi."}]},{"cve":"CVE-2021-44224","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have Apache HTTP Server as a forward or reverse proxy."}],"references":[{"category":"external","summary":"NVD - CVE-2021-44224","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44224"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have Apache HTTP Server as a forward or reverse proxy."}]},{"cve":"CVE-2022-22719","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have mod_lua."}],"references":[{"category":"external","summary":"NVD - CVE-2022-22719","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22719"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have mod_lua."}]},{"cve":"CVE-2023-27522","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi."}],"references":[{"category":"external","summary":"NVD - CVE-2023-27522","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27522"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have mod_proxy_uwsgi."}]},{"cve":"CVE-2024-38474","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not configure unsafe RewriteRules with backreferences or variable substitution."}],"references":[{"category":"external","summary":"NVD - CVE-2024-38474","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38474"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not configure unsafe RewriteRules with backreferences or variable substitution."}]},{"cve":"CVE-2024-38476","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"AN-OS is not affected as PAN-OS does not have backend application handlers vulnerable to internal redirect exploitation."}],"references":[{"category":"external","summary":"NVD - CVE-2024-38476","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38476"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"AN-OS is not affected as PAN-OS does not have backend application handlers vulnerable to internal redirect exploitation."}]},{"cve":"CVE-2024-38477","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have mod_proxy."}],"references":[{"category":"external","summary":"NVD - CVE-2024-38477","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38477"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have mod_proxy."}]},{"cve":"CVE-2024-7254","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS uses the underlying Red Hat Enterprise Linux packages which are not affected."}],"references":[{"category":"external","summary":"NVD - CVE-2024-7254","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7254"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS uses the underlying Red Hat Enterprise Linux packages which are not affected."}]},{"cve":"CVE-2026-0994","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not parse untrusted nested google.protobuf."}],"references":[{"category":"external","summary":"NVD - CVE-2026-0994","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0994"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not parse untrusted nested google.protobuf."}]},{"cve":"CVE-2026-33186","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have path-based authorization interceptors with fallback-allow policies."}],"references":[{"category":"external","summary":"NVD - CVE-2026-33186","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33186"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have path-based authorization interceptors with fallback-allow policies."}]},{"cve":"CVE-2026-39820","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have first-party code parsing mail via net/mail."}],"references":[{"category":"external","summary":"NVD - CVE-2026-39820","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have first-party code parsing mail via net/mail."}]},{"cve":"CVE-2026-39836","product_status":{"known_not_affected":["PANW-PAN-OS-1"]},"notes":[{"category":"description","text":"PAN-OS is not affected as PAN-OS does not have the vulnerable Windows functions."}],"references":[{"category":"external","summary":"NVD - CVE-2026-39836","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2026-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2026-0006"}],"threats":[{"category":"impact","description":"PAN-OS is not affected as PAN-OS does not have the vulnerable Windows functions."}]}]}