Skip to content
VulniPulse

Palo Alto Networks Security Advisories & CVEs

93 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your Palo Alto device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.

Official source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto advisories

Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45174] Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5

Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be

CVE-2026-45174
Unclassified
Jun 11, 2026
Medium4.0Palo Alto

Medium [CVE-2026-45173] Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw…

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites

CVE-2026-45173
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45172] Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5…

Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur wit

CVE-2026-45172
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45171] Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions…

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expresse

CVE-2026-45171
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45175] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation…

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be othe

CVE-2026-45175
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45178] Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.

CVE-2026-45178
Unclassified
Jun 11, 2026
Medium4.0Vendor: CriticalPalo Alto

Medium [CVE-2026-45177] Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication…

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on accoun

CVE-2026-45177
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45176] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent…

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being re

CVE-2026-45176
Unclassified
Jun 11, 2026
Critical9.3Vendor: HighPalo Alto

Critical [CVE-2026-0274] Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

CVE-2026-0274
Cortex
Jun 10, 2026
High7.5Vendor: MediumPalo Alto

High [CVE-2026-0270] Cortex XSOAR: Path Traversal Vulnerability

CVE-2026-0270 Cortex XSOAR: Path Traversal Vulnerability

CVE-2026-0270
Cortex
Jun 10, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0271] Prisma Access Agent: Local Privilege Escalation by Authorized Users

CVE-2026-0271 Prisma Access Agent: Local Privilege Escalation by Authorized Users

CVE-2026-0271
Prisma Access
Jun 10, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0272] PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

CVE-2026-0272
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
HighPalo Alto

High [CVE-2026-10000 +243] PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)

PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)

CVE-2026-10000CVE-2026-10001CVE-2026-10002+241
Unclassified
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0269] PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

CVE-2026-0269
PAN-OSFirewallPAN-OS / Panorama
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0267] GlobalProtect App: Information Exposure Vulnerability on macOS

CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS

CVE-2026-0267
GlobalProtect
Jun 10, 2026
Medium6.9Palo Alto

Medium [CVE-2026-0268] Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

CVE-2026-0268
Prisma Access
Jun 10, 2026
UnratedPalo Alto

Advisory [CVE-2025-61984 +16] PAN-SA-2026-0009 Informational Bulletin: Impact assessment of OSS CVEs in Prisma SD-WAN ION

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Prisma SD-WAN ION. While Prisma SD-WAN ION may include the affected OSS package, Prisma SD-WAN ION does not offer any scenarios required for an attacker to successfully exploit these vulnerabilities and is not impacted.

CVE-2025-61984CVE-2025-61985CVE-2026-35385+14
Unclassified
Jun 10, 2026
High7.8Palo Alto PoC reported CISA KEV

High [CVE-2026-0257] PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0257
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jun 3, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0265] PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

CVE-2026-0265
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0264] PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

CVE-2026-0264
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026

← All vendors