PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (Severity: HIGH)
CSIRTS triage
- What
- This is a monthly vulnerability update that addresses multiple vulnerabilities.
- Who is affected
- Users of Chromium and Prisma Browser are affected.
- Urgency
- Remediation is high urgency due to the severity of the vulnerabilities.
- Action
- Update to the latest version of Chromium and Prisma Browser.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium and Prisma Browser
Get an email when a new Chromium and Prisma Browser advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://security.paloaltonetworks.com/PAN-SA-2026-0010
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-108810.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108820.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108830.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108840.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108850.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108860.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108870.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108880.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108890.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108900.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Palo Alto Networks products (July 09, 2026)cert-fr-avis
- unknownCVE-2026-10935: Chromium: CVE-2026-10935 Inappropriate implementation in V8msrc
- unknownCVE-2026-10906: Chromium: CVE-2026-10906 Use after free in WebAuthenticationmsrc
- unknownCVE-2026-10882: Chromium: CVE-2026-10882 Use after free in Networkmsrc
- unknownCVE-2026-10893: Chromium: CVE-2026-10893 Use after free in Chromotingmsrc
- unknownCVE-2026-10904: Chromium: CVE-2026-10904 Inappropriate implementation in V8msrc
- unknownCVE-2026-10940: Chromium: CVE-2026-10940 Race in Codecsmsrc
- unknownCVE-2026-10926: Chromium: CVE-2026-10926 Use after free in Castmsrc
- unknownCVE-2026-10937: Chromium: CVE-2026-10937 Inappropriate implementation in Passwordsmsrc
- unknownCVE-2026-10913: Chromium: CVE-2026-10913 Use after free in ANGLEmsrc
- unknownCVE-2026-10917: Chromium: CVE-2026-10917 Insufficient validation of untrusted input in Mediamsrc
- unknownCVE-2026-10910: Chromium: CVE-2026-10910 Type Confusion in V8msrc
More from Palo Alto Networks Security Advisories
- highPAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026) (Severity: HIGH)2026-08-12
- lowCVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)2026-08-12
- mediumCVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)2026-08-12
- mediumCVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)2026-08-12
- mediumCVE-2026-0294 Prisma Access Agent: Local Privilege Escalation (Severity: MEDIUM)2026-08-12