Skip to content
VulniPulse

Palo Alto Networks Security Advisories & CVEs

41 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Palo Alto device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.

Official source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto advisories

High7.2Vendor: MediumPalo Alto Updated

High [CVE-2026-0295] GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

CVE-2026-0295
GlobalProtect
Aug 12, 2026
High8.5Vendor: MediumPalo Alto Updated

High [CVE-2026-0294] Prisma Access Agent: Local Privilege Escalation

CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation

CVE-2026-0294
Prisma Access
Aug 12, 2026
High7.4Vendor: MediumPalo Alto Updated

High [CVE-2026-0296] GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

CVE-2026-0296
GlobalProtect
Aug 12, 2026
High7.7Vendor: MediumPalo Alto Updated

High [CVE-2026-0297] GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

CVE-2026-0297
GlobalProtect
Aug 12, 2026
High8.3Vendor: MediumPalo Alto Updated

High [CVE-2026-0293] Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

CVE-2026-0293
Prisma Access
Aug 12, 2026
HighPalo Alto Updated

High [CVE-2026-0289 +448] PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026)

PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026)

CVE-2026-0289CVE-2026-0290CVE-2026-13774+446
Unclassified
Aug 12, 2026
High8.5Vendor: MediumPalo Alto Updated

High [CVE-2026-0299] GlobalProtect App: Local Privilege Escalation Vulnerabilities

CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities

CVE-2026-0299
GlobalProtect
Aug 12, 2026
High7.7Vendor: MediumPalo Alto Updated

High [CVE-2026-0298] GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

CVE-2026-0298
GlobalProtect
Aug 12, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0277] Prisma Access Agent: Improper Certificate Validation on iOS

CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS

CVE-2026-0277
Prisma Access
Jul 8, 2026
High8.4Vendor: MediumPalo Alto

High [CVE-2026-0278] Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows

CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows

CVE-2026-0278
Prisma Access
Jul 8, 2026
High7.8Vendor: MediumPalo Alto

High [CVE-2026-0283] PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)

CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)

CVE-2026-0283
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
High7.8Vendor: MediumPalo Alto

High [CVE-2026-0284] PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

CVE-2026-0284
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
High7.0Vendor: MediumPalo Alto

High [CVE-2026-0285] PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

CVE-2026-0285
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0286] PAN-OS: Authenticated Command Injection in CLI

CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI

CVE-2026-0286
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
High8.7Vendor: MediumPalo Alto

High [CVE-2026-0287] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing Affected products named by the advisory: Cloud NGFW; Prisma Access.

CVE-2026-0287
PAN-OSFirewallPrisma AccessCloud NGFW
Jul 8, 2026
HighPalo Alto Exploited CISA KEV

High [CVE-2026-0275 +529] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

CVE-2026-0275CVE-2026-10881CVE-2026-10882+527
Unclassified
Jul 8, 2026
High7.6Vendor: MediumPalo Alto

High [CVE-2026-0249] GlobalProtect App: Certificate Validation Bypass Vulnerabilities

CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities

CVE-2026-0249
GlobalProtect
Jun 13, 2026
High7.7Vendor: MediumPalo Alto

High [CVE-2026-0250] GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

CVE-2026-0250
GlobalProtect
Jun 13, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0273] PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

CVE-2026-0273
PAN-OSFirewallPAN-OS / Panorama
Jun 11, 2026
High7.5Vendor: MediumPalo Alto

High [CVE-2026-0270] Cortex XSOAR: Path Traversal Vulnerability

CVE-2026-0270 Cortex XSOAR: Path Traversal Vulnerability

CVE-2026-0270
Cortex
Jun 10, 2026

← All vendors