Skip to content
VulniPulse
Highest advisory severityCritical 2 vendors · 4 advisories

CVE-2026-4441

CVE-2026-4441: 4 tracked advisory records across Palo Alto, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

3 advisories
  • Advisory severityUnrated

    Advisory [CVE-2026-0235 +151] code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its…

    CVE-2026-0236Source published Source updated

    This bulletin covers 152 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.

    Related products — impact not confirmed
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • Prisma Browser: < 146.10.7.154
    Source-reported fixed versions
    • Prisma Browser: >= 148.6.3.96
    Mitigation guidance
    • Upgrade to a fixed release: Prisma Browser: >= 148.6.3.96.
    Workarounds
    • No known workarounds exist for this issue.
  • Advisory severityUnrated

    Advisory [CVE-2026-0235 +151] race condition vulnerability in Palo Alto Networks Prisma® Browser

    CVE-2026-0235Source published Source updated

    This bulletin covers 152 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

    Related products — impact not confirmed
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • Prisma Browser: < 146.10.7.154
    Source-reported fixed versions
    • Prisma Browser: >= 148.6.3.96
    Mitigation guidance
    • Upgrade to a fixed release: Prisma Browser: >= 148.6.3.96.
    Workarounds
    • No known workarounds exist for this issue.
  • Advisory severityUnrated

    Advisory [CVE-2026-0235 +151] improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict…

    CVE-2026-0237Source published Source updated

    This bulletin covers 152 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

    Related products — impact not confirmed
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • Prisma Browser: < 146.10.7.154
    Source-reported fixed versions
    • Prisma Browser: >= 148.6.3.96
    Mitigation guidance
    • Upgrade to a fixed release: Prisma Browser: >= 148.6.3.96.
    Workarounds
    • No known workarounds exist for this issue.

Red Hat

1 advisory
  • Advisory severityCritical9.6

    Critical [CVE-2026-4441] Use after free in Base

    CVE-2026-4441Source published

    Use after free in Base. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.

    Related products — impact not confirmed
    • Red Hat Enterprise Linux
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Red Hat rates this critical; a fix erratum may not be out yet — apply the RHSA as soon as it publishes.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery