CVE-2026-0277
CVE-2026-0277: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Palo Alto
1 advisory- Advisory severityHigh8.7
High [CVE-2026-0277] Prisma Access Agent: Improper Certificate Validation on iOS
CVE-2026-0277Source published
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
- Affected products in this advisory
- Prisma Access Agent
- Source-reported affected versions
- Prisma Access Agent < 26.2.1
- Source-reported fixed versions
- Prisma Access Agent >= 26.2.1
- Mitigation guidance
- VersionMinor VersionSuggested Solution Prisma Access Agent on iOS 25.0 through 26.2 Upgrade to 26.2.1 or later.
- Prisma Access Agent on LinuxNo action needed.Prisma Access Agent on WindowsNo action needed.Prisma Access Agent on macOSNo action needed.Prisma Access Agent on AndroidNo action needed.Prisma Access Agent on ChromeOSNo action needed.
- Workarounds
- No known workarounds exist for this issue.
Android app · Google Play
Monitor future Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.