Network security

Palo Alto Networks advisories: every record the registers tie to its products

In one line

98 advisories are attributed to Palo Alto Networks products in this record, covering March 2022 to July 2026, and 14 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 1 register entry mentions Palo Alto Networks without naming one of its products as affected, and is excluded rather than counted. Each entry below links to the register that published it.

Attributed

98

tied to a named product

Known exploited

14

in the CISA catalogue

Rated critical

16

by the register

Last checked

Jul 17, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Palo Alto Networks, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

1 entry did not clear that bar and is not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

86 of the 98 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2026-0257criticalCVSS 7.8Known exploitedMay 29, 2026

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

  • CVE-2026-0300criticalCVSS 9.3Known exploitedMay 06, 2026

    Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

  • CVE-2025-0111criticalKnown exploitedFeb 20, 2025

    Palo Alto Networks PAN-OS File Read Vulnerability

  • CVE-2025-0108criticalKnown exploitedFeb 18, 2025

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

  • CVE-2024-3393criticalKnown exploitedDec 30, 2024

    Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

  • CVE-2024-9474criticalKnown exploitedNov 18, 2024

    Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

  • CVE-2024-0012criticalKnown exploitedNov 18, 2024

    Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

  • CVE-2024-9463criticalKnown exploitedNov 14, 2024

    Palo Alto Networks Expedition OS Command Injection Vulnerability

  • CVE-2024-9465criticalKnown exploitedNov 14, 2024

    Palo Alto Networks Expedition SQL Injection Vulnerability

  • CVE-2024-5910criticalKnown exploitedNov 07, 2024

    Palo Alto Networks Expedition Missing Authentication Vulnerability

  • CVE-2024-3400criticalKnown exploitedApr 12, 2024

    Palo Alto Networks PAN-OS Command Injection Vulnerability

  • CVE-2022-0028criticalKnown exploitedAug 22, 2022

    Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

  • CVE-2017-15944criticalKnown exploitedAug 18, 2022

    Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

  • CVE-2020-2021criticalKnown exploitedMar 25, 2022

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

  • WID-SEC-2026-2261highCVSS 10.0Jul 10, 2026

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2026-2252mediumCVSS 5.3Jul 10, 2026

    Affected products: Palo Alto Networks Cortex XDR

  • CVE-2026-0275lowCVSS 2.0Jul 09, 2026

    A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on…

  • CVE-2026-0276lowCVSS 1.1Jul 09, 2026

    A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.

  • CVE-2026-0277mediumCVSS 5.7Jul 09, 2026

    An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic.

  • CVE-2026-0278mediumCVSS 5.8Jul 09, 2026

    Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.

  • CVE-2026-0279lowCVSS 1.3Jul 09, 2026

    Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto…

  • CVE-2026-0280lowCVSS 1.7Jul 09, 2026

    An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing…

  • CVE-2026-0281lowCVSS 2.1Jul 09, 2026

    An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session…

  • CVE-2026-0282lowCVSS 2.7Jul 09, 2026

    A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary…

  • CVE-2026-0283mediumCVSS 4.5Jul 09, 2026

    An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions…

  • CVE-2026-0284mediumCVSS 4.7Jul 09, 2026

    An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject…

  • CVE-2026-0285mediumCVSS 4.7Jul 09, 2026

    A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make…

  • CVE-2026-0286mediumCVSS 6.0Jul 09, 2026

    A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root.

  • CVE-2026-0287mediumCVSS 6.6Jul 09, 2026

    Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by…

  • CVE-2026-0288highCVSS 7.2Jul 08, 2026

    Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to…

  • CVE-2026-45169highCVSS 8.7Jun 12, 2026

    Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability.

  • CVE-2026-45170highCVSS 7.5Jun 12, 2026

    Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced.

  • CVE-2026-45171highCVSS 8.7Jun 11, 2026

    Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an…

  • CVE-2026-45172highCVSS 8.7Jun 11, 2026

    Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could…

  • CVE-2026-45173highCVSS 8.4Jun 11, 2026

    Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines.

  • CVE-2026-45174highCVSS 8.5Jun 11, 2026

    Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization.

  • CVE-2026-45175highCVSS 8.5Jun 11, 2026

    Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes.

  • CVE-2026-45176highCVSS 8.9Jun 11, 2026

    Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components.

  • CVE-2026-45177criticalCVSS 9.1Jun 11, 2026

    Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components.

  • CVE-2026-45178highCVSS 8.4Jun 11, 2026

    Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints.

  • WID-SEC-2026-1879highCVSS 9.8Jun 11, 2026

    Affected products: Palo Alto Networks Cortex XSOAR

  • WID-SEC-2026-1874mediumCVSS 7.2Jun 11, 2026

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2026-1873mediumCVSS 6.1Jun 11, 2026

    Affected products: Palo Alto Networks GlobalProtect

  • CVE-2026-0274highCVSS 8.1Jun 10, 2026

    An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify…

  • CVE-2026-0273mediumCVSS 6.1Jun 10, 2026

    A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user.

  • CVE-2026-0272mediumCVSS 6.0Jun 10, 2026

    A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the…

  • CVE-2026-0271mediumCVSS 5.9Jun 10, 2026

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges.

  • CVE-2026-0270mediumCVSS 4.8Jun 10, 2026

    A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept…

  • CVE-2026-0269mediumCVSS 4.6Jun 10, 2026

    A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously…

  • CVE-2026-0268mediumCVSS 4.4Jun 10, 2026

    A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.

  • CVE-2026-0267mediumCVSS 4.4Jun 10, 2026

    An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or…

  • CVE-2026-0266lowCVSS 1.1Jun 10, 2026

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.

  • WID-SEC-2026-1535highCVSS 8.8May 15, 2026

    Affected products: Palo Alto Networks GlobalProtect

  • WID-SEC-2026-1528highCVSS 9.0May 15, 2026

    Affected products: Palo Alto Networks PAN-OS

  • CVE-2026-0243mediumCVSS 4.9May 13, 2026

    A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a…

  • CVE-2026-0248mediumCVSS 6.2May 13, 2026

    An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN…

  • CVE-2026-0242mediumCVSS 6.1May 13, 2026

    A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database.

  • CVE-2026-0244mediumCVSS 5.2May 13, 2026

    An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

  • CVE-2026-0241mediumCVSS 5.1May 13, 2026

    Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

  • CVE-2026-0245mediumCVSS 4.3May 13, 2026

    Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials.

  • CVE-2026-0240mediumCVSS 4.5May 13, 2026

    An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault.

  • CVE-2026-0246mediumCVSS 5.9May 13, 2026

    A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to…

  • CVE-2026-0247mediumCVSS 5.9May 13, 2026

    Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged…

  • CVE-2026-0249mediumCVSS 4.9May 13, 2026

    Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise…

  • CVE-2026-0250mediumCVSS 5.2May 13, 2026

    A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary…

  • CVE-2026-0251mediumCVSS 5.9May 13, 2026

    Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root…

  • CVE-2026-0256mediumCVSS 4.4May 13, 2026

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web…

  • CVE-2026-0235mediumCVSS 5.8May 13, 2026

    A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

  • CVE-2026-0258mediumCVSS 4.8May 13, 2026

    A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send…

  • CVE-2026-0261mediumCVSS 6.1May 13, 2026

    Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root…

  • CVE-2026-0236highCVSS 7.3May 13, 2026

    A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user…

  • CVE-2026-0262mediumCVSS 6.6May 13, 2026

    Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by…

  • CVE-2026-0237highCVSS 7.3May 13, 2026

    An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge.

  • CVE-2026-0263highCVSS 7.2May 13, 2026

    A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated…

  • CVE-2026-0264highCVSS 7.2May 13, 2026

    A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of…

  • CVE-2026-0265highCVSS 7.2May 13, 2026

    An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud…

  • WID-SEC-2026-1366criticalCVSS 10.0May 07, 2026

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2026-1019lowCVSS 4.4Apr 13, 2026

    Affected products: Palo Alto Networks Cortex XDR

  • WID-SEC-2026-1017highCVSS 8.1Apr 13, 2026

    Affected products: Palo Alto Networks Cortex XSOAR

  • WID-SEC-2026-0701mediumCVSS 6.7Mar 12, 2026

    Affected products: Palo Alto Networks Cortex XDR

  • WID-SEC-2026-0404mediumCVSS 7.5Feb 12, 2026

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2026-0112mediumCVSS 7.5Jan 16, 2026

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2025-2583mediumCVSS 7.5Nov 14, 2025

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2025-2237mediumCVSS 6.5Oct 10, 2025

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2025-2047mediumCVSS 7.0Sep 15, 2025

    Affected products: Palo Alto Networks User-ID Agent

  • WID-SEC-2025-2035lowCVSS 2.5Sep 12, 2025

    Affected products: Palo Alto Networks Cortex XDR

  • WID-SEC-2025-1818mediumCVSS 6.8Aug 14, 2025

    Affected products: Palo Alto Networks Cortex XDR

  • WID-SEC-2025-1821mediumCVSS 6.1Aug 14, 2025

    Affected products: Palo Alto Networks Prisma Cloud

  • WID-SEC-2025-1820mediumCVSS 5.4Aug 14, 2025

    Affected products: Palo Alto Networks PAN-OS

  • WID-SEC-2025-1819mediumCVSS 6.4Aug 14, 2025

    Affected products: Palo Alto Networks GlobalProtect

  • WID-SEC-2025-1661mediumCVSS 5.5Jul 30, 2025

    Affected products: Palo Alto Networks GlobalProtect

  • WID-SEC-2025-1520mediumCVSS 6.5Jul 10, 2025

    Affected products: Palo Alto Networks GlobalProtect

  • CVE-2025-0130highCVSS 8.2May 14, 2025

    A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that…

  • CVE-2024-8686highCVSS 8.6Sep 11, 2024

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the…

  • CVE-2024-3386mediumCVSS 5.3Apr 10, 2024

    An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended.

  • CVE-2024-3385highCVSS 7.5Apr 10, 2024

    A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls.

  • CVE-2024-3382highCVSS 7.5Apr 10, 2024

    A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from…

  • CVE-2024-2433mediumCVSS 4.3Mar 13, 2024

    An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill…

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union63Jul 09, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany24Jul 10, 2026
Known Exploited Vulnerabilities catalogueCISA, United States14May 29, 2026

The entry counts here are the raw register totals for Palo Alto Networks, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Palo Alto Networks have?

98 advisories in this record are tied by a register to a product of Palo Alto Networks. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Palo Alto Networks vulnerabilities being actively exploited?

14 of the 98 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.

Why does this page show fewer CVEs for Palo Alto Networks than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 1 register entry names Palo Alto Networks without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Palo Alto Networks advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Palo Alto Networks is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Palo Alto Networks record, including sources and open questions

Palo Alto Networks vulnerabilities: all 98 advisories on record, with sources | DecisionOS by nexalign