Palo Alto Networks Security Advisories & CVEs
85 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Palo Alto device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.
Official source
Palo Alto Networks Security Advisories
Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.
Latest Palo Alto advisories
High [CVE-2026-0244] improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.
High [CVE-2026-0240] information disclosure vulnerability in Trust Protection Foundation
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.
High [CVE-2026-0241] Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
CVE-2026-0241 Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
High [CVE-2026-0242] Trust Protection Foundation: SQL Injection Vulnerability
CVE-2026-0242 Trust Protection Foundation: SQL Injection Vulnerability
High [CVE-2026-0246] Prisma Access Agent: Local Privilege Escalation Vulnerability
CVE-2026-0246 Prisma Access Agent: Local Privilege Escalation Vulnerability
High [CVE-2026-0247] Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities
CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities
Medium [CVE-2026-0245] Multiple information disclosure vulnerabilities in Prisma Access Agent®
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.
Medium [CVE-2026-0238] vulnerability in Palo Alto Networks Broker VM
A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.
Unknown [CVE-2026-0239] information disclosure vulnerability in the Chronosphere Chronocollector
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.
Unknown [CVE-2026-0235 +151] code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its…
A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.
Unknown [CVE-2026-0235 +151] race condition vulnerability in Palo Alto Networks Prisma® Browser
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.
Unknown [CVE-2026-0235 +151] improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict…
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
Critical [CVE-2026-0234] improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during…
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
High [CVE-2026-0233] certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
Medium [CVE-2026-0232] problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
High [CVE-2026-0231] information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM
An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting. The attacker must have network access to the Broker VM to exploit this issue.
Medium [CVE-2026-0230] problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
Medium [CVE-2026-2914] CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please addr
High [CVE-2026-0229] denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Medium [CVE-2026-0228] improper certificate validation vulnerability in PAN-OS
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.