Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

HighPalo Alto Exploited CISA KEV

High [CVE-2026-0275 +529] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

CVE-2026-0275CVE-2026-10881CVE-2026-10882+527
Unclassified
Jul 8, 2026
High7.8Palo Alto PoC reported CISA KEV

High [CVE-2026-0257] PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0257
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jun 3, 2026
Critical9.3Palo Alto Exploited CISA KEV

Critical [CVE-2026-0300] PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its…

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] race condition vulnerability in Palo Alto Networks Prisma® Browser

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict…

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
Critical9.3Palo Alto PoC reported CISA KEV

Critical [CVE-2024-0012 +1] PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-0012CVE-2024-9474
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Nov 18, 2024
Medium6.9Palo Alto PoC reported CISA KEV

Medium [CVE-2024-9474] PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-9474
PAN-OSFirewallCloud NGFWWildFire
Nov 18, 2024
High8.1Palo Alto Exploited CISA KEV

High [CVE-2019-1579] Palo Alto Networks GlobalProtect Portal/Gateway Interface: Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code

Palo Alto Networks is aware of the reported remote code execution (RCE) vulnerability in its GlobalProtect portal and GlobalProtect Gateway interface products. The issue is already addressed in prior maintenance releases. (Ref: CVE-2019-1579) Successful exploitation of this issue allows an unauthenticated attacker to execute arbitrary code. This issue affects PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier releases. PAN-OS 9.0 is not affected.

CVE-2019-1579
Unclassified
Jul 19, 2019