Junglewise Threat Intelligence

CVE-2026-0232: Palo Alto Networks Cortex XDR agent protection bypass on Windows

CVE-2026-0232 · Severity: medium · CVSS 4.4 · Published 2026-04-13

Vendors: Palo Alto Networks.

Executive brief

A vulnerability in the Palo Alto Networks Cortex XDR agent for Windows allows a user with administrative privileges to disable the security software. This could allow malware or a malicious actor already on the system to operate without being detected or blocked by the XDR platform. Organizations should apply the latest content updates to ensure the agent's self-protection mechanisms are functioning correctly.

Technical details

A vulnerability classified as CWE-15 (External Control of System or Configuration Setting) exists in the Palo Alto Networks Cortex XDR agent for Windows. The flaw allows a local attacker with high privileges (Windows Administrator) to bypass self-protection mechanisms and disable the agent's services. This state can be leveraged to execute malicious code or perform unauthorized activities without detection by the XDR platform. The primary fix is delivered via Content Update 2120 or higher, though several software versions (9.1.0, 9.0.1, 8.9.1, 8.7.101-CE) also include architectural hardening to address the issue.

Affected products

  • Palo Alto Networks Cortex XDR Agent 7.9-CE, 8.3-CE, 8.7-CE < 8.7.101-CE, 8.9 < 8.9.1, 9.0 < 9.0.1

Timeline

  • 2026-04-08: advisory: Initial publication by Palo Alto Networks
  • 2026-04-13: disclosed: NVD publication date

References