NCSC-2026-0227 [1.00] [M/H] Vulnerabilities fixed in Palo Alto Networks PAN-OS
Palo Alto Networks has fixed multiple vulnerabilities in PAN-OS software, specifically in PA-Series and VM-Series firewalls, as well as Panorama management platforms. The vulnerabilities affect various components of PAN-OS. - There are multiple cross-site scripting (XSS) vulnerabilities in the User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN modules, allowing unauthenticated attackers to execute arbitrary JavaScript code. - An IPv6 packet processing error allows bypassing firewall security policies, enabling access to normally protected services. - An information leak allows an unauthenticated attacker with network access to the management web interface to obtain session tokens via a malicious link. - Additionally, there is a vulnerability that allows unauthenticated attackers to delete files from a temporary folder via the management web interface. - The Large Scale VPN (LSVPN) feature has an authentication bypass flaw, allowing unauthorized users to establish site-to-site VPN connections, and an XML injection that can lead to unauthorized information access or data corruption. - A server-side request forgery (SSRF) vulnerability allows authenticated administrators to send unauthorized requests to internal services. - Furthermore, there is a command injection vulnerability in the management plane that can give authenticated administrators root access to the operating system. - Multiple denial of service (DoS) vulnerabilities can force a firewall into maintenance mode by unauthenticated attackers, disrupting normal operation. - Finally, there are buffer overflow vulnerabilities in the User-ID Terminal Server Agent that can lead to DoS or remote code execution. The Cloud NGFW and Prisma Access products are not affected by these vulnerabilities. Limiting access to the management interface to trusted internal IP addresses is recommended.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthenticated attackers to execute scripts, bypass security policies, and leak information.
- Who is affected
- Users of PA-Series and VM-Series firewalls, as well as Panorama management platforms, are affected.
- Urgency
- Remediation is urgent due to the high risk of exploitation by unauthenticated attackers.
- Action
- Update PAN-OS to the latest version to remediate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PAN-OS
Get an email when a new PAN-OS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0227
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-02790.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-02800.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-02810.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-02820.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-02830.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-02840.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all scored CVEs.
- Low exploitation riskCVE-2026-02850.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Moderate exploitation riskCVE-2026-02861.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all scored CVEs.
- Low exploitation riskCVE-2026-02870.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-02880.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-0279 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0280 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0281 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0282 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0283 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0284 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0286 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0287 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0288 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Palo Alto Networks PAN-OS: Multiple vulnerabilitiescert-bund
- highCVE-2026-0287: Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unau…nvd
- highCVE-2026-0286: A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® softwar…nvd
- mediumCVE-2026-0285: A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enable…nvd
- criticalCVE-2026-0284: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networ…nvd
- highCVE-2026-0283: An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto N…nvd
- mediumCVE-2026-0282: A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated…nvd
- highCVE-2026-0281: An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unaut…nvd
- highCVE-2026-0280: An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software…nvd
- mediumCVE-2026-0279: Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captiv…nvd
- unknownPalo Alto Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Palo Alto Networks products (July 09, 2026)cert-fr-avis
Recent advisories for Palo Alto Networks
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWcisa · 2026-07-21
- high[NEW] [high] Palo Alto Networks PAN-OS: Multiple vulnerabilitiescert-bund · 2026-07-10
- medium[NEW] [medium] Palo Alto Networks Cortex XDR Broker VM: Vulnerability allows privilege escalationcert-bund · 2026-07-10
- highCVE-2026-0276: A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a loca…nvd · 2026-07-09
- mediumCVE-2026-0275: A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a local…nvd · 2026-07-09
- highCVE-2026-0287: Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unau…nvd · 2026-07-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0268 [1.01] [M/H] Kwetsbaarheid verholpen in SQLite door SQLite Consortium (ingetrokken)2026-08-03
- unknownNCSC-2026-0275 [1.00] [M/H] Kwetsbaarheden verholpen in N-able N-central2026-08-03
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31