Skip to content
VulniPulse

Palo Alto Networks Prisma Access Vulnerabilities & Security Advisories

28 advisories tracked · Palo Alto Networks Security Advisories · 4 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Palo Alto Networks advisory that VulniPulse classified as Prisma Access, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 15 high, 8 medium.

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto Prisma Access advisories

High8.4Vendor: MediumPalo Alto

High [CVE-2026-0306] Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows

CVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows

CVE-2026-0306
Prisma Access
Sep 9, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0294] Prisma Access Agent: Local Privilege Escalation

CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation

CVE-2026-0294
Prisma Access
Aug 12, 2026
High8.3Vendor: MediumPalo Alto

High [CVE-2026-0293] Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

CVE-2026-0293
Prisma Access
Aug 12, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0277] Prisma Access Agent: Improper Certificate Validation on iOS

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.

CVE-2026-0277
Prisma Access
Jul 8, 2026
High8.4Vendor: MediumPalo Alto

High [CVE-2026-0278] Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.

CVE-2026-0278
Prisma Access
Jul 8, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0287] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities. Affected products named by the advisory: Cloud NGFW; Prisma Access.

CVE-2026-0287
PAN-OSFirewallPrisma AccessCloud NGFW
Jul 8, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0271] Prisma Access Agent: Local Privilege Escalation by Authorized Users

CVE-2026-0271 Prisma Access Agent: Local Privilege Escalation by Authorized Users

CVE-2026-0271
Prisma Access
Jun 10, 2026
High7.8Palo Alto PoC reported CISA KEV

High [CVE-2026-0257] PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0257
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jun 3, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0262] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing

CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing Affected products named by the advisory: Prisma Access.

CVE-2026-0262
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
May 28, 2026
High7.1Palo Alto

High [CVE-2026-0243] denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices

A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.

CVE-2026-0243
Prisma Access
May 13, 2026
High8.6Palo Alto

High [CVE-2026-0248] improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

CVE-2026-0248
Prisma Access
May 13, 2026
High7.7Palo Alto

High [CVE-2026-0244] improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

CVE-2026-0244
Prisma Access
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0246] Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246 Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246
Prisma Access
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0247] Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247
Prisma Access
May 13, 2026
High8.7Palo Alto

High [CVE-2026-0229] denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

CVE-2026-0229
PAN-OSFirewallPrisma AccessCloud NGFW
Feb 11, 2026

← All Palo Alto advisories