Vendor
Palo Alto Networks vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 46 vulnerabilities in Palo Alto Networks: 0 in the last 7 days and 17 in the last 90 days, 2 of them critical and 1 exploited in the wild. The most recent, CVE-2026-0304, was published on 10 September 2026. 6 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 2
- Exploited in the wild
- 1
About Palo Alto Networks
Gladinet is a software company that develops cloud file server and data management solutions.
Palo Alto Networks technologies
Latest Palo Alto Networks vulnerabilities
- CVE-2026-0304: Palo Alto Networks Cortex XDR Broker VM privilege escalationinfoCVSS 4.8EPSS 0.2%
- CVE-2026-0303: Palo Alto Networks Checkov arbitrary code execution via auto-loaded configurationinfoCVSS 2.4EPSS 0.2%
- CVE-2026-0302: Palo Alto Networks Checkov OS command injectioninfoCVSS 4.7EPSS 0.8%
- CVE-2026-0310: Palo Alto Networks PAN-OS buffer overflow in XML processinginfoCVSS 7.2EPSS 0.4%
- CVE-2026-0308: Palo Alto Networks PAN-OS stored XSS in web interfaceinfoCVSS 4.8EPSS 0.3%
- CVE-2026-0306: Palo Alto Networks Prisma Access Agent DLP bypass on WindowsinfoCVSS 5.8EPSS 0.1%
- CVE-2026-0305: Palo Alto Networks Prisma Access Agent information disclosure on LinuxinfoCVSS 4.3EPSS 0.1%
- CVE-2026-0278: Palo Alto Networks Prisma Access Agent DLP bypass on WindowsinfoCVSS 5.8
- CVE-2026-0277: Palo Alto Networks Prisma Access Agent improper certificate validation in iOSinfoCVSS 5.7
- CVE-2026-0276: Palo Alto Networks Cortex XDR Broker VM privilege escalationinfoCVSS 4.8
- CVE-2026-0275: Palo Alto Networks Prisma Browser privilege escalation in macOSinfoCVSS 7.2
- CVE-2026-0287: Palo Alto Networks PAN-OS denial of service in network traffic processinginfoCVSS 6.6
- CVE-2026-0282: Palo Alto Networks PAN-OS file deletion in management web interfaceinfoCVSS 2.7
- CVE-2026-0281: Palo Alto Networks PAN-OS information disclosure in management web interfaceinfoCVSS 2.1
- CVE-2026-0280: Palo Alto Networks PAN-OS IPv6 security policy bypass in dataplaneinfoCVSS 1.7
- CVE-2026-0279: Palo Alto Networks PAN-OS XSS in GlobalProtect and Authentication PortalinfoCVSS 5.3
- CVE-2026-0288: Palo Alto Networks PAN-OS buffer overflow in User-ID Terminal Server AgentinfoCVSS 7.2
- CVE-2026-0274: Palo Alto Networks Cortex XSOAR improper credential validation in CommvaultSecurityIQinfoCVSS 8.1
- CVE-2026-0271: Palo Alto Networks Prisma Access Agent privilege escalation in Linux appinfoCVSS 5.9
- CVE-2026-0270: Palo Alto Networks Cortex XSOAR path traversal in Linux engineinfoCVSS 4.8
- CVE-2026-0268: Palo Alto Networks Prisma Access Agent VPN bypass in LinuxinfoCVSS 4.4
- CVE-2026-0267: Palo Alto Networks GlobalProtect app information exposure on macOSinfoCVSS 4.4
- CVE-2026-0243: Palo Alto Networks Prisma SD-WAN ION denial of service via IPv6 packetmediumCVSS 6.5EPSS 0.2%
- CVE-2026-0262: Palo Alto Networks PAN-OS denial of service in traffic parsinginfoCVSS 6.6EPSS 0.1%
- CVE-2026-0261: Palo Alto Networks PAN-OS command injection in CLI and Web UIinfoCVSS 6.1EPSS 0.1%
Most severe Palo Alto Networks vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-0257: Palo Alto Networks PAN-OS auth bypass in GlobalProtectcriticalexploited in the wildCVSS 4.7EPSS 0.1%
- CVE-2026-0234: Palo Alto Networks Cortex XSOAR signature bypass in Microsoft Teams integrationcriticalCVSS 9.1EPSS 0.2%
- CVE-2026-0259: Palo Alto Networks WildFire WF-500 arbitrary file read and deletehighCVSS 8.8EPSS 0.3%
- CVE-2026-0233: Palo Alto Networks ADEM improper certificate validation on WindowshighCVSS 8.8EPSS 0.2%
- CVE-2026-0240: Palo Alto Networks Trust Protection Foundation information disclosure in vaulthighCVSS 8.7EPSS 0.2%
- CVE-2026-0250: Palo Alto Networks GlobalProtect buffer overflow in Portal/Gateway communicationhighCVSS 8.1EPSS 0.2%
- CVE-2026-0244: Palo Alto Networks Prisma SD-WAN ION improper certificate validationhighCVSS 8.1EPSS 0.1%
- CVE-2026-0247: Palo Alto Networks Prisma Access Agent authorization bypass in Endpoint DLPhighCVSS 7.8EPSS 0.2%
- CVE-2026-0251: Palo Alto Networks GlobalProtect local privilege escalationhighCVSS 7.8EPSS 0.2%
- CVE-2026-0237: Palo Alto Networks Prisma Browser security bypass in automation bridgehighCVSS 7.8EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 10 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 7 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/palo-alto-networks.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Palo Alto Networks vulnerabilities", https://junglewise.ai/threats/vendors/palo-alto-networks, 28 September 2026.