Back to vendor advisories
Palo Alto Networks Security AdvisoriesCVE-2026-0301

CVE-2026-0301: PAN-OS: Information Disclosure Vulnerability in URL Filtering

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

6.3CVSS out of 10Medium severity
Scope

What the vendor says is affected

  • Cloud NGFW
  • PAN-OS
  • Prisma Access
  • PAN-OS 12.1
  • PAN-OS 11.2
  • PAN-OS 11.1
  • PAN-OS 10.2
  • Prisma Access 12.1
  • Prisma Access 11.2
  • Prisma Access 10.2

Versions the vendor lists as fixed

  • Cloud NGFW None on AWS*, None on Azure*
  • PAN-OS 12.1 All
  • PAN-OS 11.2 All
  • PAN-OS 11.1 >= 11.1.16-h1
  • PAN-OS 10.2 >= 10.2.8
  • Prisma Access 12.1 All
  • Prisma Access 11.2 All
  • Prisma Access 10.2 >= 10.2.10
Next step

What the vendor recommends

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW* Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.1 12.1.2 through 12.1.6-h* No action needed. PAN-OS 11.2 11.2.0 through 11.2.12 No action needed. PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or later. PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.16-h1 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 12.1 12.1.2 through 12.1.* No action needed. Prisma Access 11.2 11.2.0 through 11.2* No action needed. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Palo Alto Networks

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory