<?xml version="1.0" encoding="utf-8" ?><?xml-stylesheet type="text/css" href="/css/rss.css" ?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Palo Alto Networks Security Advisories</title><description> </description><link>https://security.paloaltonetworks.com/rss.xml</link><atom:link href="https://security.paloaltonetworks.com/rss.xml" rel="self" type="application/rss+xml"></atom:link><item><title>CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI (Severity: MEDIUM)</title><pubDate>2026-06-11T01:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0273</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0273</guid></item><item><title>CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux (Severity: MEDIUM)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0268</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0268</guid></item><item><title>CVE-2026-0271 Prisma Access Agent: Local Privilege Escalation by Authorized Users (Severity: MEDIUM)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0271</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0271</guid></item><item><title>CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration (Severity: HIGH)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0274</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0274</guid></item><item><title>CVE-2026-0270 Cortex XSOAR: Path Traversal Vulnerability (Severity: MEDIUM)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0270</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0270</guid></item><item><title>PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026) (Severity: HIGH)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/PAN-SA-2026-0008</link><guid isPermaLink="true">https://security.paloaltonetworks.com/PAN-SA-2026-0008</guid></item><item><title>CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS (Severity: MEDIUM)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0267</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0267</guid></item><item><title>CVE-2026-0266 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0266</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0266</guid></item><item><title>PAN-SA-2026-0009 Informational Bulletin: Impact assessment of OSS CVEs in Prisma SD-WAN ION (Severity: INFORMATIONAL)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/PAN-SA-2026-0009</link><guid isPermaLink="true">https://security.paloaltonetworks.com/PAN-SA-2026-0009</guid></item><item><title>CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) (Severity: MEDIUM)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0272</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0272</guid></item><item><title>CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing (Severity: MEDIUM)</title><pubDate>2026-06-10T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0269</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0269</guid></item><item><title>CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities (Severity: HIGH)</title><pubDate>2026-06-03T05:45:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0257</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0257</guid></item><item><title>CVE-2026-0251 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)</title><pubDate>2026-06-02T01:15:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0251</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0251</guid></item><item><title>CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities (Severity: MEDIUM)</title><pubDate>2026-05-28T23:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0249</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0249</guid></item><item><title>CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway (Severity: MEDIUM)</title><pubDate>2026-05-28T23:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0250</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0250</guid></item><item><title>CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability (Severity: MEDIUM)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0261</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0261</guid></item><item><title>CVE-2026-0259 WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B) (Severity: MEDIUM)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0259</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0259</guid></item><item><title>CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching (Severity: MEDIUM)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0258</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0258</guid></item><item><title>CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing (Severity: MEDIUM)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0262</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0262</guid></item><item><title>CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing (Severity: HIGH)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0263</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0263</guid></item><item><title>CVE-2026-0256 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: MEDIUM)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0256</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0256</guid></item><item><title>CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled (Severity: HIGH)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0265</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0265</guid></item><item><title>CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution (Severity: HIGH)</title><pubDate>2026-05-28T21:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0264</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0264</guid></item><item><title>CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal (Severity: CRITICAL)</title><pubDate>2026-05-28T00:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0300</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0300</guid></item><item><title>CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities (Severity: MEDIUM)</title><pubDate>2026-05-13T16:00:00.000Z</pubDate><link>https://security.paloaltonetworks.com/CVE-2026-0247</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0247</guid></item></channel></rss>