PAN-SA-2026-0009 Informational Bulletin: Impact assessment of OSS CVEs in Prisma SD-WAN ION (Severity: INFORMATIONAL)
CSIRTS triage
- What
- This is an informational bulletin regarding the impact assessment of OSS CVEs.
- Who is affected
- Users of Prisma SD-WAN ION may be affected by the listed CVEs.
- Urgency
- No immediate action is required as the severity is informational.
- Action
- Review the impact assessment for relevant CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Prisma SD-WAN ION
Get an email when a new Prisma SD-WAN ION advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://security.paloaltonetworks.com/PAN-SA-2026-0009
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-353850.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-353860.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-353880.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-353870.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-354140.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-35385 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35386 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35388 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-35414 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-35414: OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios inv…msrc
- lowCVE-2026-35388: OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing ses…msrc
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Aruba AOS-CX: Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] OpenSSH: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in HPE Aruba Networking products (July 22, 2026)cert-fr-avis
- unknownUSN-8577-1: OpenSSH vulnerabilityubuntu
- unknownMultiple vulnerabilities in Red Hat Linux kernel (July 10, 2026)cert-fr-avis
- unknownUSN-8514-1: OpenSSH vulnerabilityubuntu
- unknownMultiple vulnerabilities in Red Hat Linux kernel (July 3, 2026)cert-fr-avis
- unknownRedHat Linux Kernel Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in the Red Hat Linux kernel (June 26, 2026)cert-fr-avis
More from Palo Alto Networks Security Advisories
- highPAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026) (Severity: HIGH)2026-08-12
- lowCVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)2026-08-12
- mediumCVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)2026-08-12
- mediumCVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)2026-08-12
- mediumCVE-2026-0294 Prisma Access Agent: Local Privilege Escalation (Severity: MEDIUM)2026-08-12