Skip to content
VulniPulse

Palo Alto Networks PAN-OS / Panorama Vulnerabilities & Security Advisories

30 advisories tracked · Palo Alto Networks Security Advisories · 4 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Palo Alto Networks advisory that VulniPulse classified as PAN-OS / Panorama, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 14 high, 9 medium.

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto PAN-OS / Panorama advisories

Critical9.2Vendor: HighPalo Alto Updated

Critical [CVE-2026-0310] PAN-OS: Buffer Overflow Vulnerability via XML Processing

CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing Affected products named by the advisory: Cloud NGFW; Prisma Access.

CVE-2026-0310
PAN-OSFirewallPrisma AccessCloud NGFW
Sep 9, 2026
High7.1Vendor: MediumPalo Alto Updated

High [CVE-2026-0309] PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

CVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

CVE-2026-0309
PAN-OSFirewallPAN-OS / Panorama
Sep 9, 2026
Medium4.8Vendor: LowPalo Alto Updated

Medium [CVE-2026-0308] PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

CVE-2026-0308
PAN-OSFirewallPAN-OS / Panorama
Sep 9, 2026
Medium6.3Vendor: LowPalo Alto

Medium [CVE-2026-0301] PAN-OS: Information Disclosure Vulnerability in URL Filtering

CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering Affected products named by the advisory: Cloud NGFW; Prisma Access.

CVE-2026-0301
PAN-OSFirewallPrisma AccessCloud NGFW
Aug 12, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0288] PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama is not impacted by this vulnerability. Affected products named by the advisory: Prisma Access.

CVE-2026-0288
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jul 8, 2026
High7.8Vendor: MediumPalo Alto

High [CVE-2026-0283] PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

CVE-2026-0283
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Jul 8, 2026
High7.8Vendor: MediumPalo Alto

High [CVE-2026-0284] PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

CVE-2026-0284
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Jul 8, 2026
High7.0Vendor: MediumPalo Alto

High [CVE-2026-0285] PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

CVE-2026-0285
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Jul 8, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0286] PAN-OS: Authenticated Command Injection in CLI

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

CVE-2026-0286
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Jul 8, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0287] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities. Affected products named by the advisory: Cloud NGFW; Prisma Access.

CVE-2026-0287
PAN-OSFirewallPrisma AccessCloud NGFW
Jul 8, 2026
Medium5.9Vendor: LowPalo Alto Updated

Medium [CVE-2026-0281] PAN-OS: Information Disclosure Vulnerability in Management Web Interface

CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface

CVE-2026-0281
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
Medium5.3Vendor: LowPalo Alto Updated

Medium [CVE-2026-0279] PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0279
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jul 8, 2026
Medium6.3Vendor: LowPalo Alto Updated

Medium [CVE-2026-0280] PAN-OS: IPv6 Firewall Policy Bypass

CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass Affected products named by the advisory: Prisma Access.

CVE-2026-0280
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jul 8, 2026
Medium6.9Vendor: LowPalo Alto

Medium [CVE-2026-0282] PAN-OS: File Deletion Vulnerability in Management Web Interface

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).Cloud NGFW and Prisma® Access are not impacted by this vulnerability.

CVE-2026-0282
PAN-OSFirewallCloud NGFWPAN-OS / Panorama
Jul 8, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0273] PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

CVE-2026-0273
PAN-OSFirewallPAN-OS / Panorama
Jun 11, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0272] PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

CVE-2026-0272
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0269] PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

CVE-2026-0269
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
High7.8Palo Alto PoC reported CISA KEV

High [CVE-2026-0257] PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0257
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jun 3, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0265] PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

CVE-2026-0265
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0264] PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

CVE-2026-0264
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026

← All Palo Alto advisories