Multiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Palo Alto Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une injection de code indirecte à distance (XSS).
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1156/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-843570.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760460.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-03050.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-03080.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-03030.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790160.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843480.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760200.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-03070.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843510.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Progra…cert-bund
- low[NEU] [niedrig] Palo Alto Networks Checkov by Prisma Cloud: Mehrere Schwachstellen ermöglichen Codeausführungcert-bund
- high[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellencert-bund
- high[NEU] [hoch] Palo Alto Networks GlobalProtect App: Schwachstelle ermöglicht Privilegieneskalationcert-bund
- unknownPalo Alto Networks security advisory (AV26-905)cccs
- unknownCVE-2026-0304: A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an auth…nvd
- unknownCVE-2026-0303: A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitra…nvd
- unknownCVE-2026-0302: An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a …nvd
- unknownCVE-2026-0310: A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-O…nvd
- unknownCVE-2026-0309: A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticat…nvd
- unknownCVE-2026-0308: A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enable…nvd
- unknownCVE-2026-0307: Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ ap…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans MongoDB Server (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Apereo CAS (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Check Point (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans Moodle (10 septembre 2026)2026-09-10