Palo Alto Networks PAN-OS® 软件中存在一个存储型跨站脚本(XSS)漏洞,允许恶意认证的管理员通过 Web 界面存储或执行 JavaScript 载荷。 此问题适用于 PA 系列和 VM 系列防火墙以及 Panorama(虚拟版和 M 系列)上的 PAN-OS 软件。 云下一代防火墙(Cloud NGFW)和 Prisma® Access 不受此漏洞影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | - | - |
|
| Palo Alto Networks | PAN-OS | 12.1.0 ~ 12.1.10 |
cpe:2.3:o:palo_alto_networks:pan-os:12.1.9:*:*:*:*:*:*:*
|
|
| Palo Alto Networks | Prisma Access | All ~ 12.1.4-h10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0307 | 5.9 MEDIUM | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-0306 | 5.8 MEDIUM | Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows |
| CVE-2026-0310 | 5.2 MEDIUM | PAN-OS: Buffer Overflow Vulnerability via XML Processing |
| CVE-2026-0304 | 4.8 MEDIUM | Cortex XDR Broker VM: Privilege Escalation Vulnerability |
| CVE-2026-0305 | 4.3 MEDIUM | Prisma Access Agent: Information Disclosure Vulnerability on Linux |
| CVE-2026-0309 | 4.0 MEDIUM | PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration |
| CVE-2026-0303 | 2.4 LOW | Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File |
| CVE-2026-0302 | 1.1 LOW | Checkov by Prisma Cloud: OS Command Injection Vulnerability |
No comments yet