CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0227 [1.00] [M/H] Vulnerabilities fixed in Palo Alto Networks PAN-OS

unknownCVE-2026-0279CVE-2026-0280CVE-2026-0281CVE-2026-0282CVE-2026-0283CVE-2026-0284
Palo Alto Networks has fixed multiple vulnerabilities in PAN-OS software, specifically in PA-Series and VM-Series firewalls, as well as Panorama management platforms. The vulnerabilities affect various components of PAN-OS. - There are multiple cross-site scripting (XSS) vulnerabilities in the User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN modules, allowing unauthenticated attackers to execute arbitrary JavaScript code. - An IPv6 packet processing error allows bypassing firewall security policies, enabling access to normally protected services. - An information leak allows an unauthenticated attacker with network access to the management web interface to obtain session tokens via a malicious link. - Additionally, there is a vulnerability that allows unauthenticated attackers to delete files from a temporary folder via the management web interface. - The Large Scale VPN (LSVPN) feature has an authentication bypass flaw, allowing unauthorized users to establish site-to-site VPN connections, and an XML injection that can lead to unauthorized information access or data corruption. - A server-side request forgery (SSRF) vulnerability allows authenticated administrators to send unauthorized requests to internal services. - Furthermore, there is a command injection vulnerability in the management plane that can give authenticated administrators root access to the operating system. - Multiple denial of service (DoS) vulnerabilities can force a firewall into maintenance mode by unauthenticated attackers, disrupting normal operation. - Finally, there are buffer overflow vulnerabilities in the User-ID Terminal Server Agent that can lead to DoS or remote code execution. The Cloud NGFW and Prisma Access products are not affected by these vulnerabilities. Limiting access to the management interface to trusted internal IP addresses is recommended.

CSIRTS triage

What
Multiple vulnerabilities allow unauthenticated attackers to execute scripts, bypass security policies, and leak information.
Who is affected
Users of PA-Series and VM-Series firewalls, as well as Panorama management platforms, are affected.
Urgency
Remediation is urgent due to the high risk of exploitation by unauthenticated attackers.
Action
Update PAN-OS to the latest version to remediate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch PAN-OS

Get an email when a new PAN-OS advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-13
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0227

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-0279coverage & exploitation statusNVD · CVE.org
CVE-2026-0280coverage & exploitation statusNVD · CVE.org
CVE-2026-0281coverage & exploitation statusNVD · CVE.org
CVE-2026-0282coverage & exploitation statusNVD · CVE.org
CVE-2026-0283coverage & exploitation statusNVD · CVE.org
CVE-2026-0284coverage & exploitation statusNVD · CVE.org
CVE-2026-0285coverage & exploitation statusNVD · CVE.org
CVE-2026-0286coverage & exploitation statusNVD · CVE.org
CVE-2026-0287coverage & exploitation statusNVD · CVE.org
CVE-2026-0288coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Palo Alto Networks

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories