{"id":"CVE-2026-0277","title":"An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic","summary":"An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. \n\nThe Prisma Access Agent on Windows, macOS, Linux, Android a…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-295"],"vendor":"paloaltonetworks","product":"prisma_access_agent","affected":["prisma_access_agent < 26.2.1"],"patched":["prisma_access_agent 26.2.1"],"published":"2026-07-09","updated":"2026-07-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0277","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0277","label":"psirt@paloaltonetworks.com"}],"tags":["nvd"],"epss":0.00201,"epssPercentile":0.1026,"ingestedAt":"2026-07-17T13:12:07.677Z","slug":"CVE-2026-0277","body":"## Overview\n\nAn improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. \n\nThe Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.\n\n## Affected\n\n- `prisma_access_agent < 26.2.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `prisma_access_agent 26.2.1`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}