Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Palo Alto Networks — Vulnerabilities & Security Advisories 342

Browse all 342 CVE security advisories affecting Palo Alto Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Palo Alto Networks operates as a prominent cybersecurity vendor, primarily providing next-generation firewalls, cloud security solutions, and endpoint protection platforms to enterprise clients. The company’s software ecosystem, particularly its PAN-OS operating system, has historically been associated with a significant volume of Common Vulnerabilities and Exposures, currently totaling 280 recorded instances. These vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or improper access controls within management interfaces. While the firm maintains a robust security posture through regular patching cycles and proactive threat intelligence integration, the high CVE count reflects the complexity of its extensive feature set and the broad attack surface inherent in critical infrastructure components. Major incidents have been limited, with most issues resolved via timely updates, though the sheer number of disclosed flaws underscores the challenges of securing large-scale, continuously updated network security appliances.

CVE ID Title CVSS Severity Published
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering — Cloud NGFW CWE-908 0.5 Low 2026-08-13
CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities — GlobalProtect App CWE-426 5.9 Medium 2026-08-13
CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) — GlobalProtect App CWE-94 5.2 Medium 2026-08-13
CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake — GlobalProtect App CWE-787 5.2 Medium 2026-08-13
CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability — GlobalProtect App CWE-295 4.5 Medium 2026-08-13
CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS — GlobalProtect App CWE-362 4.1 Medium 2026-08-13
CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation — Prisma Access Agent CWE-427 6.0 Medium 2026-08-13
CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows — Prisma Access Agent CWE-693 5.6 Medium 2026-08-13
CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows — Prisma Access Agent CWE-290 2.1 Low 2026-08-13
CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux — Prisma Access Agent CWE-59 1.1 Low 2026-08-13
CVE-2026-0290 Prisma Browser: Sensitive Information Disclosure Vulnerability — Prisma Browser CWE-522 0.5 Low 2026-08-13
CVE-2026-0289 Prisma Browser: Inappropriate Implementation in Account Protection — Prisma Browser CWE-522 0.5 Low 2026-08-13
CVE-2026-0275 Prisma Browser: Local Privilege Escalation on macOS — Prisma Browser CWE-269 - - 2026-07-09
CVE-2026-0276 Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability — Cortex XDR Broker VM CWE-269 - - 2026-07-09
CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS — Prisma Access Agent CWE-295 - - 2026-07-09
CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows — Prisma Access Agent CWE-693 - - 2026-07-09
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities — Cloud NGFW CWE-79 0.4 Low 2026-07-09
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass — Cloud NGFW CWE-131 1.7 Low 2026-07-09
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface — Cloud NGFW CWE-524 1.7 Low 2026-07-09
CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface — Cloud NGFW CWE-20 1.2 Low 2026-07-09
CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) — Cloud NGFW CWE-306 4.5 Medium 2026-07-09
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) — Cloud NGFW CWE-74 4.7 Medium 2026-07-09
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface — Cloud NGFW CWE-918 4.4 Medium 2026-07-09
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI — Cloud NGFW CWE-78 6.0 Medium 2026-07-09
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing — Cloud NGFW CWE-754 4.6 Medium 2026-07-09
CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent — Cloud NGFW CWE-787 4.8 Medium 2026-07-08
CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration — Cortex XSIAM CommvaultSecurityIQ Marketplace CWE-1390 - - 2026-06-10
CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI — Cloud NGFW CWE-78 5.7 Medium 2026-06-10
CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) — Cloud NGFW CWE-862 5.6 Medium 2026-06-10
CVE-2026-0271 Prisma Access Agent: Local Privilege Escalation by Authorized Users — Prisma Access Agent CWE-732 - - 2026-06-10

This page lists every published CVE security advisory associated with Palo Alto Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.