Skip to content
VulniPulse

Palo Alto Networks PAN-OS Vulnerabilities & Security Advisories

30 advisories tracked · Palo Alto Networks Security Advisories · 4 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Palo Alto Networks advisory that VulniPulse classified as PAN-OS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 14 high, 9 medium.

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto PAN-OS advisories

Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0263] PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing

CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing

CVE-2026-0263
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
Critical9.3Palo Alto Exploited CISA KEV

Critical [CVE-2026-0300] PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0261] PAN-OS: Authenticated Admin Command Injection Vulnerability

CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability

CVE-2026-0261
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0262] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing

CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing Affected products named by the advisory: Prisma Access.

CVE-2026-0262
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
May 28, 2026
High8.3Vendor: MediumPalo Alto

High [CVE-2026-0258] PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching

CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching

CVE-2026-0258
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
High8.7Palo Alto

High [CVE-2026-0229] denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

CVE-2026-0229
PAN-OSFirewallPrisma AccessCloud NGFW
Feb 11, 2026
Medium5.3Palo Alto

Medium [CVE-2026-0228] improper certificate validation vulnerability in PAN-OS

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

CVE-2026-0228
PAN-OSFirewallPAN-OS / Panorama
Feb 11, 2026
High8.7Palo Alto

High [CVE-2026-0227] vulnerability in Palo Alto Networks PAN-OS software

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

CVE-2026-0227
PAN-OSFirewallPAN-OS / Panorama
Jan 15, 2026
Critical9.3Palo Alto PoC reported CISA KEV

Critical [CVE-2024-0012 +1] PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-0012CVE-2024-9474
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Nov 18, 2024
Medium6.9Palo Alto PoC reported CISA KEV

Medium [CVE-2024-9474] PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-9474
PAN-OSFirewallCloud NGFWWildFire
Nov 18, 2024

← All Palo Alto advisories