Palo Alto Networks PAN-OS Vulnerabilities & Security Advisories
30 advisories tracked · Palo Alto Networks Security Advisories · 4 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Palo Alto Networks advisory that VulniPulse classified as PAN-OS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 14 high, 9 medium.
Android app · Google Play
Monitor Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Source
Palo Alto Networks Security Advisories
Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.
Latest Palo Alto PAN-OS advisories
Medium [CVE-2026-0308] PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Medium [CVE-2026-0301] PAN-OS: Information Disclosure Vulnerability in URL Filtering
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering Affected products named by the advisory: Cloud NGFW; Prisma Access.
Medium [CVE-2026-0281] PAN-OS: Information Disclosure Vulnerability in Management Web Interface
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Medium [CVE-2026-0279] PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities Affected products named by the advisory: Prisma Access.
Medium [CVE-2026-0280] PAN-OS: IPv6 Firewall Policy Bypass
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass Affected products named by the advisory: Prisma Access.
Medium [CVE-2026-0282] PAN-OS: File Deletion Vulnerability in Management Web Interface
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
Medium [CVE-2026-0269] PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
Medium [CVE-2026-0228] improper certificate validation vulnerability in PAN-OS
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
Medium [CVE-2024-9474] PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances. Cloud NGFW and Prisma Access are not impacted by this vulnerability.