Vendor advisories

Palo Alto Networks Security Advisories

Browse 39 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 12 minutes ago Checked every 15 minutes

39 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Palo Alto Networks Security AdvisoriesPAN-SA-2026-0010
CriticalCVSS 9.2

PAN-SA-2026-0010: Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

Palo Alto Networks incorporated the following Chromium security fixes into our products: * https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html

Affected productsPrisma Browser
Fixed versionsPrisma Browser >= 150.33.2.46
Vendor guidance

CVE PRISMA BROWSER CVE-2026-10881 149.10.3.53 CVE-2026-10882 149.10.3.53 CVE-2026-10883 149.10.3.53 CVE-2026-10884 149.10.3.53 CVE-2026-10885 149.10.3.53 CVE-2026-10886 149.10.3.53 CVE-2026-10887 149.10.3.53 CVE-2026-...

Palo Alto Networks Security AdvisoriesCVE-2026-0288
CriticalCVSS 9.2

CVE-2026-0288: PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sendi...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW All on AWS, All on Azure unless you have been contacted by Palo Alto Networks, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN...

Palo Alto Networks Security AdvisoriesCVE-2026-0287
HighCVSS 8.7

CVE-2026-0287: PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attem...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW None on AWS, None on Azure, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION RANGE SUGGESTED SOLUTION Cloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrad...

Palo Alto Networks Security AdvisoriesCVE-2026-0285
HighCVSS 7.0

CVE-2026-0285: PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by ...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW All, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN...

Palo Alto Networks Security AdvisoriesCVE-2026-0284
HighCVSS 7.8

CVE-2026-0284: PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal L...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW All, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION RANGE SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or late...

Palo Alto Networks Security AdvisoriesCVE-2026-0283
HighCVSS 7.8

CVE-2026-0283: PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and Pr...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW All, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later....

Palo Alto Networks Security AdvisoriesCVE-2026-0286
HighCVSS 8.5

CVE-2026-0286: PAN-OS: Authenticated Command Injection in CLI

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW All, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later....

Palo Alto Networks Security AdvisoriesCVE-2026-0278
HighCVSS 8.4

CVE-2026-0278: Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.

Affected productsPrisma Access Agent, Prisma Access Agent 0
Fixed versionsPrisma Access Agent 0 >= 26.2.1 on Windows, Prisma Access Agent All on macOS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Prisma Access Agent on Windows 24.0 through 26.2 Upgrade to 26.2.1 or later. Prisma Access Agent on macOS No action needed.

Palo Alto Networks Security AdvisoriesCVE-2026-0280
MediumCVSS 6.3

CVE-2026-0280: PAN-OS: IPv6 Firewall Policy Bypass

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panor...

Affected productsCloud NGFW, PAN-OS, Panorama, Prisma Access
Fixed versionsCloud NGFW All, PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8, PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13, PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN...

Palo Alto Networks Security AdvisoriesCVE-2026-0249
HighCVSS 7.6

CVE-2026-0249: GlobalProtect App: Certificate Validation Bypass Vulnerabilities

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attac...

Affected productsGlobalProtect App, GlobalProtect App 6.3, GlobalProtect App 6.2, GlobalProtect App 6.1
Fixed versionsGlobalProtect App 6.3 >= 6.3.3-h9 (6.3.3-999) on macOS, GlobalProtect App 6.2 >= 6.2.8-h10 (6.2.8-948) on macOS, GlobalProtect App 6.1 >= 6.1.14 on Android, >= 6.1.14 on ChromeOS, GlobalProtect App 6.0 >= 6.0.14 on Android, >= 6.0.14 on ChromeOS, >= 6.0.13 on macOS
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.1 on Android 6.1.0 through 6.1.13 Upgrade to 6.1.14 or later. GlobalProtect App 6.0 on Android 6.0.0 through 6.0.13 Upgrade to 6.0.14 or later. GlobalProtec...

Palo Alto Networks Security AdvisoriesPAN-SA-2026-0009
InformationalCVSS 0.0

PAN-SA-2026-0009: Informational Bulletin: Impact assessment of OSS CVEs in Prisma SD-WAN ION

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Prisma SD-WAN ION. While Prisma SD-WAN ION may include the affected OSS package, Prisma SD-WAN ION does not offer any scenarios required for an ...

Affected productsPrisma SD-WAN ION
Fixed versionsPrisma SD-WAN ION All
Vendor guidance

No software updates are required at this time.

Palo Alto Networks Security AdvisoriesCVE-2026-0246
HighCVSS 8.5

CVE-2026-0246: Prisma Access Agent: Local Privilege Escalation Vulnerability

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execu...

Affected productsPrisma Access Agent
Fixed versionsPrisma Access Agent >= 26.2.1 on Linux, >= 26.2.1 on macOS, >= 26.2.1 on Windows, Prisma Access Agent All on Android, All on ChromeOS, All on iOS
Vendor guidance

Version Minor Version Suggested Solution Prisma Access Agent on Linux 25.0 through 26.2 Upgrade to 26.2.1 or later. Prisma Access Agent on macOS 24.0 through 26.2 Upgrade to 26.2.1 or later. Prisma Access Agent on Win...

Palo Alto Networks Security AdvisoriesPAN-SA-2026-0005
InformationalCVSS 0.0

PAN-SA-2026-0005: Informational Bulletin: Precautionary Fixes for Non-Exploitable OSS CVEs in PAN-OS

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. These CVEs were determined to have no impact on PAN-OS, but they have been fixed out of an abundance of caution.

Affected productsPAN-OS
Fixed versionsPAN-OS All
Vendor guidance

The OSS CVEs are fixed in the respective PAN-OS versions.

Palo Alto Networks Security AdvisoriesPAN-SA-2026-0006
InformationalCVSS 0.0

PAN-SA-2026-0006: Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the affected OSS package, PAN-OS does not offer any scenarios required for an attacker to suc...

Affected productsPAN-OS
Fixed versionsPAN-OS All
Vendor guidance

The OSS CVEs are fixed in the respective PAN-OS versions.

Palo Alto Networks Security AdvisoriesCVE-2025-4619
HighCVSS 8.7

CVE-2025-4619: PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets

A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance m...

Affected productsCloud NGFW, PAN-OS, Prisma Access, PAN-OS 12.1
Fixed versionsCloud NGFW All, PAN-OS 12.1 All, PAN-OS 11.2 >= 11.2.2-h2, >= 11.2.3-h6, >= 11.2.4-h4, >= 11.2.5, PAN-OS 11.1 < 11.1.2-h9, >= 11.1.2-h18, < 11.1.3-h2, < 11.1.4-h4, >= 11.1.4-h13, >= 11.1.6-h1, >= 11.1.7
Vendor guidance

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 No action needed. PAN-OS 11.2 11.2.0 through 11.2.4 Upgrade to 11.2.4-h4 or 11.2.5 or later. 11.2.0 through 11.2.3 Upgrade to 11.2.3-h6...

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.