← Back

Paloaltonetworks

paloaltonetworks

371 CVEs • 125 products

Products (125)

Click to collapse
Toggle
Pan Os
pan-os
Globalprotect
globalprotect
Expedition
expedition
Cortex Xsoar
cortex_xsoar
Prisma Access
prisma_access
Prisma Cloud
prisma_cloud
Traps
traps
Secdo
secdo
Prisma Sd Wan
prisma_sd-wan
Netconnect
netconnect
Demisto
demisto
Minemeld
minemeld
Twistlock
twistlock
Vm Series
vm-series
Cortex Xsiam
cortex_xsiam
Cloud Ngfw
cloud_ngfw
Broker Vm
broker_vm
Pa 7050
pa-7050
Pa 7080
pa-7080
Pa 200
pa-200
Pa 2020
pa-2020
Pa 2050
pa-2050
Pa 220
pa-220
Pa 3020
pa-3020
Pa 3050
pa-3050
Pa 3060
pa-3060
Pa 3220
pa-3220
Pa 3250
pa-3250
Pa 3260
pa-3260
Pa 500
pa-500
Pa 5200
pa-5200
Pa 800
pa-800
Pa 5410
pa-5410
Pa 5420
pa-5420
Pa 5430
pa-5430
Pa 5440
pa-5440
Pa 5445
pa-5445
Pa 1410
pa-1410
Pa 1420
pa-1420
Pa 3410
pa-3410
Pa 3420
pa-3420
Pa 3430
pa-3430
Pa 3440
pa-3440
Pa 410
pa-410
Pa 410r
pa-410r
Pa 410r 5g
pa-410r-5g
Pa 415
pa-415
Pa 415 5g
pa-415-5g
Pa 440
pa-440
Pa 445
pa-445
Pa 450
pa-450
Pa 450r
pa-450r
Pa 450r 5g
pa-450r-5g
Pa 455
pa-455
Pa 455 5g
pa-455-5g
Pa 455r 5g
pa-455r-5g
Pa 460
pa-460
Pa 501
pa-501
Pa 505
pa-505
Pa 510
pa-510
Pa 520
pa-520
Pa 540
pa-540
Pa 545 Poe
pa-545-poe
Pa 5450
pa-5450
Pa 550
pa-550
Pa 5540
pa-5540
Pa 555 Poe
pa-555-poe
Pa 5550
pa-5550
Pa 5560
pa-5560
Pa 5570
pa-5570
Pa 5580
pa-5580
Pa 560
pa-560
Pa 7500
pa-7500
Pa 7500 Dpc A
pa-7500-dpc-a

CVEs (371)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Expedition
Jun 17, 2026
Oct 9, 2024
9.9 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, dev...Show more
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Sep 11, 2024
5.3 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by...Show more
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Sep 11, 2024
5.6 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disa...Show more
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Sep 11, 2024
6.7 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI...Show more
An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.Show less
1Paloaltonetworks
3Globalprotect
Pan OsPrisma Access
Jun 17, 2026
Sep 11, 2024
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconn...Show more
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Sep 11, 2024
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Aug 14, 2024
6.0 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator w...Show more
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Aug 14, 2024
5.2 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
1Paloaltonetworks
1Cortex Xsoar Commonscripts
Jun 17, 2026
Aug 14, 2024
7.0 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 10, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 10, 2024
7.0 HIGH· v4
4.9 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeat...Show more
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.Show less
1Paloaltonetworks
1Expedition
Jun 17, 2026
Jul 10, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in conf...Show more
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Jun 12, 2024
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the C...Show more
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Jun 12, 2024
5.5 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable...Show more
A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Jun 12, 2024
5.2 MEDIUM· v4
7.0 HIGH· v3
N/A· v2
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to...Show more
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.Show less
1Paloaltonetworks
1Prisma Cloud
Jun 17, 2026
Jun 12, 2024
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the we...Show more
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Jun 12, 2024
2.0 LOW· v4
4.4 MEDIUM· v3
N/A· v2
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to dis...Show more
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.Show less
7Cisco
CitrixF5+4 more
9Anyconnect Vpn Client
Big Ip Access Policy ManagerClient Connector+6 more
Jun 17, 2026
May 6, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface....Show more
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Apr 12, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an u...Show more
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.Show less
1Paloaltonetworks
2Pan Os
Prisma Access
Jun 17, 2026
Apr 10, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability do...Show more
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.Show less