VulnSea

Palo Alto Networks has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 4.3 (medium). None have a confirmed exploitation report. Most affected products: Cloud NGFW (3), Checkov by Prisma Cloud (2), Prisma Access Agent (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
4.3
Publish → KEV
Last 90 days
9 prev 0

Products

  • Cloud NGFW 3
  • Checkov by Prisma Cloud 2
  • Prisma Access Agent 2
  • Cortex XDR Broker VM 1
  • GlobalProtect App 1
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Palo Alto Networks vulnerabilities

CVEs affecting Palo Alto Networks, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-0303Low· 2.4PoC
1w ago

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

TwilightPalo Alto Networks · Checkov by Prisma CloudEPSS 0.13%via NVD
CVE-2026-0310High· 7.2
1w ago

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …

TwilightPalo Alto Networks · Cloud NGFWEPSS 0.34%via NVD
CVE-2026-0302Low· 1.1
1w ago

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

SunlitPalo Alto Networks · Checkov by Prisma CloudEPSS 0.82%via NVD
CVE-2026-0304Medium· 4.8
1w ago

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

SunlitPalo Alto Networks · Cortex XDR Broker VMEPSS 0.22%via NVD
CVE-2026-0309Medium· 4.0
1w ago

PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

SunlitPalo Alto Networks · Cloud NGFWEPSS 0.45%via CVEORG
CVE-2026-0307Medium· 5.9
1w ago

GlobalProtect App: Local Privilege Escalation Vulnerabilities

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administr…

SunlitPalo Alto Networks · GlobalProtect AppEPSS 0.10%via CVEORG
CVE-2026-0308Low· 1.1
1w ago

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-…

SunlitPalo Alto Networks · Cloud NGFWEPSS 0.27%via NVD
CVE-2026-0306Medium· 5.8
1w ago

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Ac…

SunlitPalo Alto Networks · Prisma Access AgentEPSS 0.10%via NVD
CVE-2026-0305Medium· 4.3
1w ago

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and C…

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and C…

SunlitPalo Alto Networks · Prisma Access AgentEPSS 0.10%via NVD
Palo Alto Networks vulnerabilities (CVEs) · VulnSea