Junglewise Threat Intelligence

CVE-2026-0244: Palo Alto Networks Prisma SD-WAN ION improper certificate validation

CVE-2026-0244 · Severity: high · CVSS 8.1 · Published 2026-05-13

Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks Prisma SD-WAN ION devices, which are used to manage and secure corporate wide-area networks, contain a security flaw in how they verify digital certificates. An attacker positioned on the local network could exploit this to impersonate the central management controller. If successful, this could allow the attacker to intercept sensitive data, modify network configurations, or disrupt connectivity.

Technical details

An improper certificate validation vulnerability (CWE-295) exists in the Palo Alto Networks Prisma SD-WAN ION software. The flaw stems from the device failing to correctly validate the identity of the controller during communication. An attacker with adjacent network access can exploit this to perform a man-in-the-middle (MitM) attack, allowing them to impersonate the controller and intercept or modify traffic. The vulnerability is addressed in versions 6.3.6-b10, 6.4.3-b8, and 6.5.3-b15 or later.

Affected products

  • Palo Alto Networks Prisma SD-WAN ION 6.3.1 to 6.3.6-b10; 6.4.1 to 6.4.3-b8; 6.5.1 to 6.5.3-b15

Timeline

  • 2026-05-13: disclosed: Initial publication by Palo Alto Networks
  • 2026-05-13: patched: Fixes released in updated software versions

References

Related threats