By vendor

Paloaltonetworks vulnerabilities

Known CVEs affecting Paloaltonetworks products, prioritized by severity, with SEC.co remediation and detection guidance.

30 published vulnerabilities

  • CVE-2026-45170HIGH 8.8

    Idira Vendor PAM Self-Hosted Connector versions before 1.1.100504 contain a flaw in how they validate TLS certificates. Under specific conditions and configurations, the connector may not properly enforce certificate validation, potentially allowing an attacker on the same network segment to intercept or manipulate encrypted communications. This is a serious issue because PAM solutions are trusted with sensitive credentials and authentication tokens—weakened encryption validation undermines that trust.

  • CVE-2026-45171HIGH 8.8

    CVE-2026-45171 is a high-severity vulnerability in Idira Privileged Session Manager that allows authenticated users with basic (low-privileged) access to execute arbitrary code on affected systems. The flaw stems from incomplete validation of user input combined with overly permissive folder access controls. An attacker who already has login credentials—even with minimal permissions—could exploit this to gain full system control, making it a critical concern for organizations relying on PSM for credential and session management.

  • CVE-2026-45172HIGH 8.8

    Idira Privileged Session Manager for SSH (PSMP) contains a flaw that allows authenticated users with basic system access to run arbitrary commands on the PSMP host itself. An attacker who already has valid credentials and low-level permissions—perhaps a contractor or junior staff member—could exploit incomplete input validation to escalate their privileges and take full control of the session management system. This is particularly dangerous because PSMP systems typically guard access to critical infrastructure and administrative credentials.

  • CVE-2026-45169HIGH 8.6

    Idira Privileged Access Manager Self-Hosted Vault contains a flaw in how it validates certain inputs. When specific conditions and configurations align, an attacker can send specially crafted requests over the network that cause the vault service to crash unexpectedly. While the service is down, legitimate users cannot access their privileged credentials, creating a denial-of-service condition. The vulnerability affects multiple older versions of the product, though patches have been released.

  • CVE-2026-45178HIGH 8.1

    Idira Secrets Manager Self-Hosted versions 13.8.0 and earlier contain a flaw that allows authenticated users with basic node-level credentials to access internal cluster communication channels they shouldn't be able to reach. An attacker with valid login credentials could exploit these unsecured endpoints to steal secrets stored in the system or disrupt its availability. The vulnerability requires prior authentication, so it represents an insider or compromised-credential risk rather than an unauthenticated attack vector.

  • CVE-2026-0271HIGH 7.8

    A privilege escalation vulnerability exists in Palo Alto Networks' Prisma Access Agent on Linux systems. An attacker with local access to an affected Linux device can exploit this flaw to gain elevated privileges and run code with higher permissions than their current account level. This capability is limited to Linux deployments; Windows, macOS, iOS, Android, and ChromeOS installations are unaffected.

  • CVE-2026-0276HIGH 7.8

    A privilege escalation flaw in Palo Alto Networks Cortex XDR Broker VM allows a user with local access to the system to gain root-level control. An authenticated attacker could exploit this to execute arbitrary commands with the highest privileges, potentially compromising the security monitoring infrastructure itself.

  • CVE-2026-0278HIGH 7.8

    A local user on Windows can circumvent data loss prevention (DLP) controls in Palo Alto Networks' Prisma Access Agent by exploiting multiple protection mechanism failures. An attacker with local access can bypass the DLP policies meant to prevent sensitive data from leaving the system. This vulnerability requires local access and does not affect the macOS version of Prisma Access Agent.

  • CVE-2026-45174HIGH 7.8

    CVE-2026-45174 is a privilege escalation vulnerability in Palo Alto Networks' Idira Endpoint Privilege Manager Linux Agent that allows a local user with basic system access to compromise the agent daemon during its initialization. An attacker with low-level user privileges can exploit weak initialization controls to gain unauthorized system access with full read, write, and execute capabilities on the affected system. The vulnerability affects all Linux Agent versions before 26.5.

  • CVE-2026-45175HIGH 7.8

    Idira Endpoint Privilege Manager Agent (versions before 26.5) has a flaw in how it validates itself and enforces security rules. A local user on an affected system could exploit this weakness to bypass the agent's built-in protections and potentially execute actions that should be blocked. The vulnerability requires local access and authenticated login, but once exploited, could allow unauthorized operations at a high privilege level.

  • CVE-2026-45176HIGH 7.8

    Idira Endpoint Privilege Manager Agent contains a flaw in how it controls access to high-privileged components. An attacker with a regular user account on the same system can manipulate how the agent communicates internally or intercept file operations to trick it into performing actions it shouldn't allow. This could let them gain elevated privileges and take unauthorized actions on the machine. The vulnerability affects versions before 26.5.

  • CVE-2026-0270HIGH 7.5

    Palo Alto Networks Cortex XSOAR running on Linux contains a flaw that lets an attacker on the same network write files to the server if they can intercept and modify network traffic in transit. The vulnerability requires the attacker to be positioned to perform a man-in-the-middle attack, but once they are, they can exploit the path traversal weakness to place arbitrary files on the host system. This is a significant risk in environments where XSOAR is exposed to untrusted network segments or where network security controls may be incomplete.

  • CVE-2026-0287HIGH 7.5

    Palo Alto Networks PAN-OS firewalls contain multiple denial of service vulnerabilities that allow unauthenticated attackers on the network to crash the firewall by sending specially crafted traffic through dataplane interfaces. Repeating this attack forces the firewall into maintenance mode, effectively taking it offline. Panorama management systems are not affected. This is a network-accessible vulnerability requiring no authentication, making it a significant availability risk for organizations relying on these firewalls for critical security functions.

  • CVE-2026-0288HIGH 7.5

    Palo Alto Networks PAN-OS contains multiple buffer overflow flaws in the User-ID Terminal Server Agent (TSA) component that can be exploited over the network without authentication. An attacker can send malformed network traffic to trigger a denial of service or potentially run arbitrary code on affected firewalls. However, the risk is substantially reduced if you follow Palo Alto's deployment guidance and restrict TSA connectivity to trusted internal IP addresses only. Panorama appliances are not affected.

  • CVE-2026-0272HIGH 7.2

    CVE-2026-0272 is a privilege escalation flaw in Palo Alto Networks PAN-OS that lets an authenticated administrator with CLI access run commands as root. While the vulnerability requires pre-existing admin credentials and CLI access, the impact is severe: a malicious or compromised admin account could gain unrestricted control of the firewall. The risk is substantially reduced when CLI access is tightly limited to a small trusted group and the management interface is restricted to known internal IP ranges.

  • CVE-2026-0273HIGH 7.2

    A command injection flaw in Palo Alto Networks PAN-OS allows any authenticated administrator who can reach the CLI or web management interface to execute arbitrary commands with root privileges. The vulnerability affects PA-Series, VM-Series firewalls, and Panorama deployments, but not Cloud NGFW or Prisma Access. While the flaw requires legitimate admin credentials to exploit, an insider threat or compromised admin account could lead to complete system compromise. The risk is materially lower when CLI access is tightly restricted and the management interface is isolated to trusted internal networks only.

  • CVE-2026-0280HIGH 7.2

    Palo Alto Networks PAN-OS has a flaw in how it processes IPv6 traffic at the firewall level. An attacker on the network can craft malicious IPv6 packets that bypass the firewall's security policies, allowing blocked traffic to slip through to protected systems. This doesn't require authentication or user interaction—just the ability to send traffic toward the firewall. Cloud NGFW and Panorama deployments are unaffected.

  • CVE-2026-0283HIGH 7.2

    Palo Alto Networks PAN-OS contains an authentication bypass flaw in its Large Scale VPN (LSVPN) feature that allows attackers with network access to establish unauthorized site-to-site VPN connections without proper credentials. The vulnerability affects multiple PAN-OS versions and creates a direct path for lateral movement and network compromise. Panorama, Cloud NGFW, and Prisma Access deployments are not affected.

  • CVE-2026-0286HIGH 7.2

    An authenticated administrator with access to PAN-OS management interfaces can inject commands into the system in a way that allows execution of arbitrary operating system commands with root privileges. The vulnerability exists in the management plane of Palo Alto Networks firewalls and Panorama deployments. Because exploitation requires an authenticated administrator account, the actual risk depends heavily on how tightly you control who has CLI access to your management infrastructure.

  • CVE-2026-0281HIGH 7.1

    An unauthenticated attacker can trick a legitimate user into clicking a malicious link that allows the attacker to steal their web session token for the Palo Alto Networks firewall management interface. This token grants access to sensitive firewall configuration and monitoring capabilities. The attack requires both network access to the management interface and social engineering to get a user to click the link, but once successful, the attacker can impersonate that user without needing their password.

  • CVE-2026-0275MEDIUM 6.7

    Palo Alto Networks Prisma Browser on macOS contains a local privilege escalation flaw that allows an authenticated administrator with filesystem access to execute commands with root-level privileges. The vulnerability requires the attacker to already have admin access and local system access, significantly limiting its exposure. This is not a remote attack vector and does not affect Prisma Browser on other operating systems.

  • CVE-2026-0282MEDIUM 6.5

    Palo Alto Networks PAN-OS contains a vulnerability that allows an attacker on the network to delete files from a temporary directory on the management interface without authentication. The actual risk depends heavily on your deployment posture—Palo Alto emphasizes that restricting management access to trusted internal networks significantly reduces exposure. Cloud NGFW and Prisma Access deployments are unaffected.

  • CVE-2026-45173MEDIUM 6.5

    Idira Identity Browser Extension, a credential and identity management tool available for Chrome, Firefox, and Edge, contains a flaw in how it validates the origin of web pages before executing sensitive operations. An attacker could create a malicious webpage that tricks an already-logged-in user into triggering unauthorized actions within their authenticated session. The vulnerability affects all versions before 26.8.1 and requires user interaction—specifically navigation to a crafted site—to exploit.

  • CVE-2026-0279MEDIUM 6.1

    Palo Alto Networks PAN-OS contains multiple cross-site scripting (XSS) vulnerabilities in its User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN components. An unauthenticated attacker can inject malicious JavaScript that either persists in the system or executes in a user's browser. The vulnerability requires user interaction (such as clicking a malicious link) to trigger. Palo Alto's deployment best practices—restricting management interface and Authentication Portal access to trusted internal IP addresses—significantly reduce exposure.

  • CVE-2026-0277MEDIUM 5.9

    CVE-2026-0277 is a certificate validation flaw in Palo Alto Networks' Prisma Access Agent for iOS that allows an attacker positioned on the network to intercept and potentially manipulate VPN traffic. Because the iOS agent fails to properly validate SSL/TLS certificates, an attacker can impersonate legitimate VPN endpoints and decrypt traffic, compromising the confidentiality of data meant to be protected by the VPN. The vulnerability requires network positioning (such as on a shared Wi-Fi network or compromised network infrastructure) but no user interaction or authentication. Windows, macOS, Linux, Android, and ChromeOS variants of the Prisma Access Agent are not vulnerable.

  • CVE-2026-0269MEDIUM 5.7

    An authenticated attacker can cause a Palo Alto Networks PAN-OS firewall to reboot by sending specially crafted packets that exploit a memory corruption flaw in tunnel traffic processing. Sending multiple malicious packets repeatedly forces the firewall into maintenance mode, rendering it unavailable until manual intervention occurs. This is not a remote unauthenticated attack—the attacker must already have network access and valid credentials.

  • CVE-2026-0267MEDIUM 5.5

    A vulnerability in Palo Alto Networks' GlobalProtect app for macOS allows a local user to read stored passcodes that protect critical app functions. Once an attacker learns these passcodes, they can disable, disconnect, or uninstall GlobalProtect even when the app's security policy would normally prevent such actions. This is a local-only risk that requires prior access to the affected macOS device.

  • CVE-2026-0285MEDIUM 4.9

    A vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators with access to the management interface to make unauthorized requests from the firewall itself to internal services. This server-side request forgery (SSRF) flaw could enable an admin to pivot toward backend systems or services that should only be reachable from within the firewall's network. The risk is materially reduced if you follow Palo Alto Networks' recommended practice of restricting management interface access to trusted internal IP addresses only.

  • CVE-2026-0266MEDIUM 4.8

    A stored cross-site scripting (XSS) vulnerability exists in Palo Alto Networks PAN-OS that allows an authenticated administrator to inject malicious JavaScript into the web interface. The payload persists in the system and executes when other users access the affected interface, potentially compromising their sessions or stealing sensitive data. The vulnerability requires valid administrator credentials to exploit, which significantly limits the attack surface but remains a genuine concern for insider threats or compromised admin accounts.

  • CVE-2026-0268MEDIUM 4.4

    A vulnerability in Palo Alto Networks' Prisma Access Agent for Linux allows a local user on an affected system to bypass security controls and route network traffic outside the intended VPN tunnel. This is a local attack that requires an authenticated user account and does not affect Windows, macOS, iOS, Android, or ChromeOS deployments. An attacker exploiting this could potentially access resources or send data outside the VPN tunnel without proper security monitoring.