Palo Alto Networks PAN-OS® 软件中的 XML 处理功能存在缓冲区溢出漏洞。具备网络访问权限的未认证攻击者(可访问管理 Web 接口或数据平面接口)利用该漏洞,可在 VM 系列防火墙上引发拒绝服务(DoS)状况,或在 PA 系列防火墙上以 root 权限执行任意代码。 根据我们推荐的最佳实践部署指南(https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | All | - |
|
| Palo Alto Networks | PAN-OS | 12.2.0 ~ 12.2.3 |
cpe:2.3:o:palo_alto_networks:pan-os:12.2.2:*:*:*:*:*:*:*
|
|
| Palo Alto Networks | Prisma Access | 11.2.0 ~ 11.2.4-h21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0307 | 5.9 MEDIUM | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-0306 | 5.8 MEDIUM | Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows |
| CVE-2026-0304 | 4.8 MEDIUM | Cortex XDR Broker VM: Privilege Escalation Vulnerability |
| CVE-2026-0305 | 4.3 MEDIUM | Prisma Access Agent: Information Disclosure Vulnerability on Linux |
| CVE-2026-0309 | 4.0 MEDIUM | PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration |
| CVE-2026-0303 | 2.4 LOW | Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File |
| CVE-2026-0302 | 1.1 LOW | Checkov by Prisma Cloud: OS Command Injection Vulnerability |
| CVE-2026-0308 | 0.4 LOW | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface |
No comments yet