Skip to content
VulniPulse

Palo Alto Networks Security Advisories & CVEs

30 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Palo Alto device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.

Official source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto advisories

Medium4.8Vendor: LowPalo Alto

Medium [CVE-2026-0266] PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

CVE-2026-0266 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

CVE-2026-0266
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0268] Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

CVE-2026-0268
Prisma Access
Jun 10, 2026
Medium6.8Palo Alto

Medium [CVE-2026-0245] Multiple information disclosure vulnerabilities in Prisma Access Agent®

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.

CVE-2026-0245
Prisma Access
May 13, 2026
Medium4.8Palo Alto

Medium [CVE-2026-0238] vulnerability in Palo Alto Networks Broker VM

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

CVE-2026-0238
Unclassified
May 13, 2026
Medium6.7Palo Alto

Medium [CVE-2026-0232] problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

CVE-2026-0232
Cortex
Apr 13, 2026
Medium6.7Palo Alto

Medium [CVE-2026-0230] problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

CVE-2026-0230
Cortex
Mar 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-2914] CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please addr

CVE-2026-2914
Unclassified
Feb 25, 2026
Medium5.3Palo Alto

Medium [CVE-2026-0228] improper certificate validation vulnerability in PAN-OS

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

CVE-2026-0228
PAN-OSFirewallPAN-OS / Panorama
Feb 11, 2026
Medium4.0Palo Alto

Medium [CVE-2026-1723] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection. This issue affects X6000R: through V9.4.0cu.1498_B20250826. Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be me

CVE-2026-1723
Unclassified
Jan 30, 2026
Medium6.9Palo Alto PoC reported CISA KEV

Medium [CVE-2024-9474] PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-9474
PAN-OSFirewallCloud NGFWWildFire
Nov 18, 2024

← All vendors