Junglewise Threat Intelligence

CVE-2026-0277: Palo Alto Networks Prisma Access Agent improper certificate validation in iOS

CVE-2026-0277 · Severity: info · CVSS 5.7 · Published 2026-07-09

Technologies: Palo Alto Networks Prisma Access Agent. Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks Prisma Access Agent is a mobile application used to provide secure VPN connectivity for remote workers. A security flaw in the iOS version of this app could allow an attacker on the same local network (such as public Wi-Fi) to intercept and view sensitive corporate data. This could lead to the exposure of login credentials or confidential business communications.

Technical details

An improper certificate validation vulnerability (CWE-295) exists in the Prisma Access Agent for iOS. The flaw stems from the application failing to correctly verify the authenticity of the server's SSL/TLS certificate during the connection process. An attacker positioned on an adjacent network (such as the same Wi-Fi segment) can exploit this by presenting a fraudulent certificate, enabling a Man-in-the-Middle (MitM) attack. Successful exploitation allows the attacker to decrypt, view, or modify VPN traffic. The issue is fixed in version 26.2.1; other platforms like Windows, macOS, and Android are not affected.

Affected products

  • Palo Alto Networks Prisma Access Agent iOS versions 25.0 through 26.2; fixed in 26.2.1

Timeline

  • 2026-07-08: disclosed: Discovered internally by Palo Alto Networks
  • 2026-07-08: advisory
  • 2026-07-09: patched: Version 26.2.1 released to address the issue

References

Related threats