Palo Alto Networks PAN-OS / Panorama Vulnerabilities & Security Advisories
30 advisories tracked · Palo Alto Networks Security Advisories · 4 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Palo Alto Networks advisory that VulniPulse classified as PAN-OS / Panorama, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 14 high, 9 medium.
Android app · Google Play
Monitor Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Source
Palo Alto Networks Security Advisories
Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.
Latest Palo Alto PAN-OS / Panorama advisories
High [CVE-2026-0309] PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
CVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
High [CVE-2026-0283] PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0284] PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0285] PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0286] PAN-OS: Authenticated Command Injection in CLI
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
High [CVE-2026-0287] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities. Affected products named by the advisory: Cloud NGFW; Prisma Access.
High [CVE-2026-0273] PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
High [CVE-2026-0272] PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
High [CVE-2026-0257] PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities Affected products named by the advisory: Prisma Access.
High [CVE-2026-0261] PAN-OS: Authenticated Admin Command Injection Vulnerability
CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability
High [CVE-2026-0262] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing Affected products named by the advisory: Prisma Access.
High [CVE-2026-0258] PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
High [CVE-2026-0229] denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
High [CVE-2026-0227] vulnerability in Palo Alto Networks PAN-OS software
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.