Back to vendor advisories
Palo Alto Networks Security AdvisoriesCVE-2026-0279

CVE-2026-0279: PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431). This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.

5.3CVSS out of 10Medium severity
Scope

What the vendor says is affected

  • Cloud NGFW
  • PAN-OS
  • Prisma Access
  • PAN-OS 12.1
  • PAN-OS 11.2
  • PAN-OS 11.1
  • PAN-OS 10.2
  • Prisma Access 12.1
  • Prisma Access 11.2
  • Prisma Access 10.2

Versions the vendor lists as fixed

  • Cloud NGFW All
  • PAN-OS 12.1 >= 12.1.8
  • PAN-OS 11.2 >= 11.2.13
  • PAN-OS 11.1 >= 11.1.16
  • PAN-OS 10.2 None
  • Prisma Access 12.1 >= 12.1.8*
  • Prisma Access 11.2 None*
  • Prisma Access 10.2 None*
Next step

What the vendor recommends

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.2 through 12.1.7-h* Upgrade to 12.1.8 or later. PAN-OS 11.2 11.2.0 through 11.2.12 Upgrade to 11.2.13 or later. PAN-OS 11.1 11.1.0 through 11.1.15-h* Upgrade to 11.1.16 or later. PAN-OS 10.2 10.2.0 through 10.2* Upgrade to 11.1.16, 11.2.13, 12.1.8 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 12.1 12.1.2 through 12.1.7-h* Upgrade to 12.1.8 or later.* Prisma Access 11.2 11.2.0 through 11.2* Upgrade to 12.1.8 or later.* Prisma Access 10.2 10.2.0 through 10.2* Upgrade to 12.1.8 or later.* * See the note under Product Status for information regarding Prisma Access upgrades.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Palo Alto Networks

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory