Palo Alto Networks Security Advisories
Palo Alto Networks publishes security advisories for PAN-OS, GlobalProtect, Prisma and Cortex products. Like other perimeter-security vendors, its critical advisories are high-value targets for attackers and regularly end up in the CISA KEV catalog.
CSIRTS.com ingests Palo Alto Networks Security Advisories every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes security advisories for PAN-OS and related products. Also available via RSS, JSON API and the MCP server.
Latest from Palo Alto Networks Security Advisories
CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)
CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)
CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)
CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)
CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway (Severity: MEDIUM)
CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File (Severity: LOW)
CVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows (Severity: MEDIUM)
CVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux (Severity: MEDIUM)
CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)
PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) (Severity: HIGH)
CVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability (Severity: LOW)
CVE-2026-0307 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)
CVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration (Severity: MEDIUM)
CVE-2026-0304 Cortex XDR Broker VM: Privilege Escalation Vulnerability (Severity: MEDIUM)
CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)
CVE-2026-0251 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: HIGH)
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)
CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux (Severity: LOW)
CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation (Severity: MEDIUM)
PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026) (Severity: HIGH)
CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows (Severity: LOW)
CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows (Severity: MEDIUM)
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities (Severity: LOW)
PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (Severity: HIGH)
Browse all 63 advisories from Palo Alto Networks Security Advisories →
Never miss a Palo Alto Networks Security Advisories advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.