Multiple vulnerabilities in Palo Alto Networks products (August 13, 2026)
Multiple vulnerabilities have been discovered in Palo Alto Networks products. Some of them allow an attacker to cause arbitrary remote code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities allow arbitrary remote code execution, privilege escalation, and remote denial of service in Palo Alto Networks products.
- Who is affected
- Deployments running affected Palo Alto Networks products; specific versions and products not detailed.
- Urgency
- High urgency; remote code execution and privilege escalation are critical but no active exploitation reported.
- Action
- Contact Palo Alto Networks for affected product versions and apply available patches immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1014/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-138480.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-140980.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137910.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-141040.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-139340.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-140800.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151180.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-138060.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-141000.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-139330.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownPalo Alto Products Multiple Vulnerabilitieshkcert
- high[NEW] [high] Palo Alto Networks GlobalProtect App: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Palo Alto Networks PAN-OS: Vulnerability enables information disclosurecert-bund
- unknownCVE-2026-0301: An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-…nvd
- unknownCVE-2026-0299: Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable …nvd
- unknownCVE-2026-0295: A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally aut…nvd
- highPAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026) (Severity: HIGH)paloalto
- mediumCVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)paloalto
- lowCVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)paloalto
- mediumCVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)paloalto
- high[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- high[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
Recent advisories for Palo Alto Networks
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellencert-bund · 2026-09-11
- high[NEU] [hoch] Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Progra…cert-bund · 2026-09-10
- low[NEU] [niedrig] Palo Alto Networks Checkov by Prisma Cloud: Mehrere Schwachstellen ermöglichen Codeausführungcert-bund · 2026-09-10
- high[NEU] [hoch] Palo Alto Networks GlobalProtect App: Schwachstelle ermöglicht Privilegieneskalationcert-bund · 2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)cccs · 2026-09-10
- unknownCVE-2026-0304: A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an auth…nvd · 2026-09-10
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Laravel (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Veeam (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Apereo CAS (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)2026-09-10