VulnSea

paloaltonetworks has 42 CVEs on record between 2019 and 2026. Cadence is steady at roughly 20 per quarter. The busiest recent month was June 2026 with 10. The median CVSS is 7.2 (high), with 5 rated critical. 10% have been exploited in the wild, in line with the corpus average. When CISA adds a paloaltonetworks CVE to KEV it happens fast: a median of 3 days after publication (4 cases). The dominant weakness classes are CWE-295 (3) and CWE-306 (3). Most affected products: pan-os (16), prisma_access_agent (7), globalprotect (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
10% vs 1% corpus
Median CVSS
7.2
Publish → KEV
3 d median(4)
Last 90 days
20 prev 18

Products

  • pan-os 16
  • prisma_access_agent 7
  • globalprotect 5
  • prisma_browser 3
  • trust_protection_foundation 2
  • autonomous_digital_experience_manager 1
42
Total CVEs
5
Critical
4
CISA KEV
4
Exploited

paloaltonetworks vulnerabilities

CVEs affecting paloaltonetworks, newest first. Open any entry for full detail, references, and exploit status.

42 CVEsRSS

CVE-2026-0295High· 7.0⚖ disputed
1mo ago

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.07%via NVD
CVE-2026-0289Medium· 6.5⚖ disputed
1mo ago

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

▾ Sunlitpaloaltonetworks · prisma_browserEPSS 0.22%via NVD
CVE-2026-0292Medium· 6.0⚖ disputed
1mo ago

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.13%via NVD
CVE-2026-0290Medium· 5.5⚖ disputed
1mo ago

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

▾ Sunlitpaloaltonetworks · prisma_browserEPSS 0.13%via NVD
CVE-2026-0298High· 8.1⚖ disputed
1mo ago

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbi…

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbi…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.33%via NVD
CVE-2026-0297High· 8.1⚖ disputed
1mo ago

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated priv…

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated priv…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.31%via NVD
CVE-2026-0296High· 7.4
1mo ago

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is no…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.14%via NVD
CVE-2026-0294High· 7.8
1mo ago

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, an…

▾ Twilightpaloaltonetworks · prisma_access_agentEPSS 0.11%via NVD
CVE-2026-0293Medium· 6.0
1mo ago

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma…

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.11%via NVD
CVE-2026-0291Medium· 4.4
1mo ago

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma A…

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma A…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.11%via NVD
CVE-2026-0277Medium· 5.9
2mo ago

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android a…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.20%via NVD
CVE-2026-0286High· 7.2
2mo ago

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly m…

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly m…

▾ Twilightpaloaltonetworks · pan-osEPSS 1.7%via NVD
CVE-2026-0285Medium· 4.9
2mo ago

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to intern…

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to intern…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.43%via NVD
CVE-2026-0284Critical· 9.9
2mo ago

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to informatio…

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to informatio…

▾ Midnightpaloaltonetworks · pan-osEPSS 0.46%via NVD
CVE-2026-0283High· 7.2
2mo ago

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN …

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN …

▾ Twilightpaloaltonetworks · pan-osEPSS 0.38%via NVD
CVE-2026-0282Medium· 6.5
2mo ago

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this iss…

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this iss…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.29%via NVD
CVE-2026-0281High· 7.1
2mo ago

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first…

▾ Twilightpaloaltonetworks · pan-osEPSS 0.28%via NVD
CVE-2026-0280High· 7.2
2mo ago

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach …

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach …

▾ Twilightpaloaltonetworks · pan-osEPSS 0.34%via NVD
CVE-2026-0279Medium· 6.1
2mo ago

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauth…

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauth…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.75%via NVD
CVE-2026-0287High· 7.5
2mo ago

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or throu…

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or throu…

▾ Twilightpaloaltonetworks · cloud_ngfwEPSS 0.62%via NVD
CVE-2026-45169High· 8.6
3mo ago

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could …

▾ Twilightpaloaltonetworks · idira_privileged_access_manager_vaultEPSS 0.63%via NVD
CVE-2026-0269Medium· 5.7
3mo ago

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a rebo…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.22%via NVD
CVE-2026-0268Medium· 4.4
3mo ago

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.10%via NVD
CVE-2026-0266Medium· 4.8
3mo ago

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.14%via NVD
CVE-2026-0274Critical· 9.1
3mo ago

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

▾ Midnightpaloaltonetworks · cortex_xsiam_commvaultsecurityiq_marketplaceEPSS 0.29%via NVD
CVE-2026-0273High· 7.2PoC
3mo ago

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

▾ Midnightpaloaltonetworks · pan-osEPSS 1.3%via NVD
CVE-2026-0272High· 7.2
3mo ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk…

▾ Twilightpaloaltonetworks · pan-osEPSS 0.26%via NVD
CVE-2026-0271High· 7.8
3mo ago

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iO…

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iO…

▾ Twilightpaloaltonetworks · prisma_access_agentEPSS 0.11%via NVD
CVE-2026-0270High· 7.5
3mo ago

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a ma…

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a ma…

▾ Twilightpaloaltonetworks · cortex_xsoarEPSS 0.20%via NVD
CVE-2026-0267Medium· 5.5
3mo ago

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is …

▾ Sunlitpaloaltonetworks · globalprotectEPSS 0.10%via NVD
paloaltonetworks vulnerabilities (CVEs) · VulnSea