Skip to content
VulniPulse

Palo Alto Networks Security Advisories & CVEs

93 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your Palo Alto device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.

Official source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto advisories

Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0263] PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing

CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing

CVE-2026-0263
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
Critical9.3Palo Alto Exploited CISA KEV

Critical [CVE-2026-0300] PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
High7.1Vendor: MediumPalo Alto

High [CVE-2026-0259] WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)

CVE-2026-0259 WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)

CVE-2026-0259
WildFire
May 28, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0261] PAN-OS: Authenticated Admin Command Injection Vulnerability

CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability

CVE-2026-0261
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0262] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing

CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing Affected products named by the advisory: Prisma Access.

CVE-2026-0262
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
May 28, 2026
High8.3Vendor: MediumPalo Alto

High [CVE-2026-0258] PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching

CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching

CVE-2026-0258
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
High7.1Palo Alto

High [CVE-2026-0243] denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices

A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.

CVE-2026-0243
Prisma Access
May 13, 2026
High8.6Palo Alto

High [CVE-2026-0248] improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

CVE-2026-0248
Prisma Access
May 13, 2026
High7.7Palo Alto

High [CVE-2026-0244] improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

CVE-2026-0244
Prisma Access
May 13, 2026
High7.4Palo Alto

High [CVE-2026-0240] information disclosure vulnerability in Trust Protection Foundation

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

CVE-2026-0240
Unclassified
May 13, 2026
High7.2Vendor: MediumPalo Alto

High [CVE-2026-0241] Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

CVE-2026-0241 Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

CVE-2026-0241
Unclassified
May 13, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0242] Trust Protection Foundation: SQL Injection Vulnerability

CVE-2026-0242 Trust Protection Foundation: SQL Injection Vulnerability

CVE-2026-0242
Unclassified
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0246] Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246 Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246
Prisma Access
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0247] Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247
Prisma Access
May 13, 2026
Medium6.8Palo Alto

Medium [CVE-2026-0245] Multiple information disclosure vulnerabilities in Prisma Access Agent®

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.

CVE-2026-0245
Prisma Access
May 13, 2026
Medium4.8Palo Alto

Medium [CVE-2026-0238] vulnerability in Palo Alto Networks Broker VM

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

CVE-2026-0238
Unclassified
May 13, 2026
UnratedPalo Alto

Advisory [CVE-2026-0239] information disclosure vulnerability in the Chronosphere Chronocollector

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

CVE-2026-0239
Unclassified
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its…

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] race condition vulnerability in Palo Alto Networks Prisma® Browser

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026
UnratedPalo Alto Exploited CISA KEV

Advisory [CVE-2026-0235 +151] improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict…

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

CVE-2026-0235CVE-2026-0235146CVE-2026-0236+149
Prisma Access
May 13, 2026

← All vendors