Skip to content
VulniPulse
Medium6.7Palo Alto Networks

Medium [CVE-2026-0232] problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows

This medium-severity Palo Alto Networks advisory covers CVE-2026-0232 affecting Cortex XDR.

CVE-2026-0232 Published Apr 13, 2026Updated by vendor Jun 17, 2026
Affected products & platforms
Palo Alto NetworksCortex
Open vendor advisory

Android app · Google Play

Monitor future Palo Alto Networks CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

Affected versions
  • Cortex XDR Agent < 9.0.1
  • Cortex XDR Agent < 8.9.1
  • Cortex XDR Agent < 8.7.101-CE
  • Cortex XDR Agent 8.3-CE
  • Cortex XDR Agent 7.9-CE

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • Cortex XDR Agent >= 9.0.1
  • Cortex XDR Agent >= 8.9.1
  • Cortex XDR Agent >= 8.7.101-CE
  • Cortex XDR Agent >= 8.3-CE
  • Cortex XDR Agent >= 7.9-CE

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To fully remediate this vulnerability, customers must ensure their Content Update is at version 2120 or higher.
  • This update provides the necessary protection across all supported versions of Cortex XDR.
  • While the Content Update provides the primary fix, the following software releases include complementary architectural enhancements to further harden the environment:
Workaround status
  • No known workarounds exist for this issue.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.