Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Cloud NGFW — Vulnerabilities & Security Advisories 65

All 65 CVE vulnerabilities found in Cloud NGFW, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregation for Palo Alto Networks Cloud NGFW, categorized by weakness type. It serves as a centralized resource for understanding security gaps associated with this specific cloud-native firewall solution. The collection encompasses a wide range of vulnerability classifications, including buffer overflows, cross-site scripting, and privilege escalation flaws, spanning from the product's initial public release through recent patches. This comprehensive timeline allows users to observe how security postures have evolved alongside feature updates and threat landscape changes. Visitors can efficiently track vendor advisories to stay informed about newly disclosed issues and recommended remediation steps. By examining the aggregated data, users gain deeper insight into common weakness classes, such as those defined in the Common Weakness Enumeration (CWE), and understand their specific impact on cloud infrastructure. The page also enables the lookup of a product’s historical vulnerability record, providing context for current risk assessments and helping teams prioritize remediation efforts based on severity and exploitability. Whether you are a security administrator reviewing patch notes or a developer analyzing code integrity, this resource offers structured access to critical security intelligence. It supports informed decision-making by consolidating disparate vulnerability reports into a coherent view, facilitating proactive defense strategies and compliance verification.

Vendor: Palo Alto Networks

CVE IDTitleCVSSSeverityPublished
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering CWE-908 0.5 Low2026-08-13
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities CWE-79 0.4 Low2026-07-09
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass CWE-131 1.7 Low2026-07-09
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface CWE-524 1.7 Low2026-07-09
CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface CWE-20 1.2 Low2026-07-09
CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) CWE-306 4.5 Medium2026-07-09
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) CWE-74 4.7 Medium2026-07-09
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface CWE-918 4.4 Medium2026-07-09
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI CWE-78 6.0 Medium2026-07-09
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing CWE-754 4.6 Medium2026-07-09
CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent CWE-787 4.8 Medium2026-07-08
CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI CWE-78 5.7 Medium2026-06-10
CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) CWE-862 5.6 Medium2026-06-10
CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing CWE-754--2026-06-10
CVE-2026-0266 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface CWE-79 0.4 Low2026-06-10
CVE-2026-0256 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface CWE-79--2026-05-13
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities CWE-565--2026-05-13
CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching CWE-918--2026-05-13
CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability CWE-78--2026-05-13
CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing CWE-754--2026-05-13
CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing CWE-787--2026-05-13
CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution CWE-122--2026-05-13
CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled CWE-347--2026-05-13
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal CWE-787 9.8AICriticalAI2026-05-06
CVE-2026-0229 PAN-OS: Denial of Service in Advanced DNS Security Feature CWE-754 7.5AIHighAI2026-02-11
CVE-2026-0228 PAN-OS: Improper Validation of Terminal Server Agent Certificate CWE-295 7.5AIHighAI2026-02-11
CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal CWE-754 7.5AIHighAI2026-01-15
CVE-2025-4619 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets CWE-754 7.5 -2025-11-13
CVE-2025-4615 PAN-OS: Improper Neutralization of Input in the Management Web Interface CWE-83 7.2AIHighAI2025-10-09
CVE-2025-4614 PAN-OS: Session Token Disclosure Vulnerability CWE-497 4.9AIMediumAI2025-10-09

All 65 known CVE vulnerabilities affecting Cloud NGFW with full Chinese analysis, references, and POCs where available.