Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-0248

CVE-2026-0248: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityHigh8.6

    High [CVE-2026-0248] improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS

    CVE-2026-0248Source published Source updated

    An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

    Related products — impact not confirmed
    • Prisma Access
    Source-reported affected versions
    • Prisma Access Agent < 26.2.1
    Source-reported fixed versions
    • Prisma Access Agent >= 26.2.1
    Mitigation guidance
    • Upgrade to a fixed release: Prisma Access Agent >= 26.2.1.
    Workarounds
    • No known workarounds exist for this issue.

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery