Skip to content
VulniPulse

Palo Alto Networks Prisma Access Vulnerabilities & Security Advisories

28 advisories tracked · Palo Alto Networks Security Advisories · 4 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Palo Alto Networks advisory that VulniPulse classified as Prisma Access, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 15 high, 8 medium.

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto Prisma Access advisories

High7.7Palo Alto

High [CVE-2026-0244] improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

CVE-2026-0244
Prisma Access
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0246] Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246 Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246
Prisma Access
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0247] Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247
Prisma Access
May 13, 2026
Medium6.8Palo Alto

Medium [CVE-2026-0245] Multiple information disclosure vulnerabilities in Prisma Access Agent®

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.

CVE-2026-0245
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its…

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] race condition vulnerability in Palo Alto Networks Prisma® Browser

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict…

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
High8.7Palo Alto

High [CVE-2026-0229] denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

CVE-2026-0229
PAN-OSFirewallPrisma AccessCloud NGFW
Feb 11, 2026

← All Palo Alto advisories