VulnSea

paloaltonetworks has 42 CVEs on record between 2019 and 2026. Cadence is steady at roughly 20 per quarter. The busiest recent month was June 2026 with 10. The median CVSS is 7.2 (high), with 5 rated critical. 10% have been exploited in the wild, in line with the corpus average. When CISA adds a paloaltonetworks CVE to KEV it happens fast: a median of 3 days after publication (4 cases). The dominant weakness classes are CWE-295 (3) and CWE-306 (3). Most affected products: pan-os (16), prisma_access_agent (7), globalprotect (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
10% vs 1% corpus
Median CVSS
7.2
Publish → KEV
3 d median(4)
Last 90 days
20 prev 18

Products

  • pan-os 16
  • prisma_access_agent 7
  • globalprotect 5
  • prisma_browser 3
  • trust_protection_foundation 2
  • autonomous_digital_experience_manager 1
42
Total CVEs
5
Critical
4
CISA KEV
4
Exploited

paloaltonetworks vulnerabilities

CVEs affecting paloaltonetworks, newest first. Open any entry for full detail, references, and exploit status.

42 CVEsRSS

CVE-2026-0239Medium· 6.5
4mo ago

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

▾ Sunlitpaloaltonetworks · chronosphere_collectorEPSS 0.17%via NVD
CVE-2026-0241High· 7.2
4mo ago

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

▾ Twilightpaloaltonetworks · trust_protection_foundationEPSS 0.34%via NVD
CVE-2026-0240High· 8.7
4mo ago

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate an…

▾ Twilightpaloaltonetworks · trust_protection_foundationEPSS 0.24%via NVD
CVE-2026-0238Low· 3.2
4mo ago

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

▾ Sunlitpaloaltonetworks · broker_vmEPSS 0.10%via NVD
CVE-2026-0236High· 7.8
4mo ago

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to …

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to …

▾ Twilightpaloaltonetworks · prisma_browserEPSS 0.16%via NVD
CVE-2026-0234Critical· 9.1
5mo ago

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

▾ Midnightpaloaltonetworks · cortex_xsiamEPSS 0.23%via NVD
CVE-2026-0233High· 8.8
5mo ago

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

▾ Twilightpaloaltonetworks · autonomous_digital_experience_managerEPSS 0.18%via NVD
CVE-2026-0232Medium· 4.4
5mo ago

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

▾ Sunlitpaloaltonetworks · cortex_xdr_agentEPSS 0.15%via NVD
CVE-2025-0108Critical· 9.1CISA KEVPoC
1y ago

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

▾ Hadalpaloaltonetworks · pan-osEPSS 98%via NVD
CVE-2024-9474High· 7.2CISA KEV0dayPoC
1y ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 95%via NVD
CVE-2024-0012Critical· 9.8CISA KEV0dayPoC
1y ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

▾ Hadalpaloaltonetworks · pan-osEPSS 100%via NVD
CVE-2019-1579High· 8.1CISA KEVPoC
7y ago

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 46%via NVD
paloaltonetworks vulnerabilities (CVEs) — page 2 · VulnSea