CVE-2026-0248
CVE-2026-0248: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Palo Alto
1 advisory- Advisory severityHigh8.6
High [CVE-2026-0248] improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS
CVE-2026-0248Source published Source updated
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.
- Related products — impact not confirmed
- Prisma Access
- Source-reported affected versions
- Prisma Access Agent < 26.2.1
- Source-reported fixed versions
- Prisma Access Agent >= 26.2.1
- Mitigation guidance
- Upgrade to a fixed release: Prisma Access Agent >= 26.2.1.
- Workarounds
- No known workarounds exist for this issue.
Android app · Google Play
Monitor future Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.