Multiple vulnerabilities in Palo Alto Networks products (July 09, 2026)
Multiple vulnerabilities have been discovered in Palo Alto Networks products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and a remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote arbitrary code execution, privilege escalation, and a remote denial of service.
- Who is affected
- Deployments of various Palo Alto Networks products are affected.
- Urgency
- Remediation urgency is unknown due to unspecified severity.
- Action
- Monitor for updates and apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0853/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-109270.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-109910.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-116370.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-112390.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-111820.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-109860.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-109550.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-111440.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-02810.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-110410.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0227 [1.00] [M/H] Vulnerabilities fixed in Palo Alto Networks PAN-OSncsc-nl
- high[NEW] [high] Palo Alto Networks PAN-OS: Multiple vulnerabilitiescert-bund
- highCVE-2026-0283: An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto N…nvd
- highCVE-2026-0281: An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unaut…nvd
- unknownPalo Alto Products Multiple Vulnerabilitieshkcert
- mediumCVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) (Severity: MEDIUM)paloalto
- lowCVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface (Severity: LOW)paloalto
- highPAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (Severity: HIGH)paloalto
- unknownCVE-2026-10991: Chromium: CVE-2026-10991 Use after free in V8msrc
- unknownCVE-2026-11668: Chromium: CVE-2026-11667 Out of bounds read in WebRTCmsrc
- unknownCVE-2026-11175: Chromium: CVE-2026-11175 Incorrect security UI in Messagesmsrc
- unknownCVE-2026-11144: Chromium: CVE-2026-11144 Use after free in Mediamsrc
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21