← Back

Paloaltonetworks

paloaltonetworks

371 CVEs • 125 products

Products (125)

Click to collapse
Toggle
Pan Os
pan-os
Globalprotect
globalprotect
Expedition
expedition
Cortex Xsoar
cortex_xsoar
Prisma Access
prisma_access
Prisma Cloud
prisma_cloud
Traps
traps
Secdo
secdo
Prisma Sd Wan
prisma_sd-wan
Netconnect
netconnect
Demisto
demisto
Minemeld
minemeld
Twistlock
twistlock
Vm Series
vm-series
Cortex Xsiam
cortex_xsiam
Cloud Ngfw
cloud_ngfw
Broker Vm
broker_vm
Pa 7050
pa-7050
Pa 7080
pa-7080
Pa 200
pa-200
Pa 2020
pa-2020
Pa 2050
pa-2050
Pa 220
pa-220
Pa 3020
pa-3020
Pa 3050
pa-3050
Pa 3060
pa-3060
Pa 3220
pa-3220
Pa 3250
pa-3250
Pa 3260
pa-3260
Pa 500
pa-500
Pa 5200
pa-5200
Pa 800
pa-800
Pa 5410
pa-5410
Pa 5420
pa-5420
Pa 5430
pa-5430
Pa 5440
pa-5440
Pa 5445
pa-5445
Pa 1410
pa-1410
Pa 1420
pa-1420
Pa 3410
pa-3410
Pa 3420
pa-3420
Pa 3430
pa-3430
Pa 3440
pa-3440
Pa 410
pa-410
Pa 410r
pa-410r
Pa 410r 5g
pa-410r-5g
Pa 415
pa-415
Pa 415 5g
pa-415-5g
Pa 440
pa-440
Pa 445
pa-445
Pa 450
pa-450
Pa 450r
pa-450r
Pa 450r 5g
pa-450r-5g
Pa 455
pa-455
Pa 455 5g
pa-455-5g
Pa 455r 5g
pa-455r-5g
Pa 460
pa-460
Pa 501
pa-501
Pa 505
pa-505
Pa 510
pa-510
Pa 520
pa-520
Pa 540
pa-540
Pa 545 Poe
pa-545-poe
Pa 5450
pa-5450
Pa 550
pa-550
Pa 5540
pa-5540
Pa 555 Poe
pa-555-poe
Pa 5550
pa-5550
Pa 5560
pa-5560
Pa 5570
pa-5570
Pa 5580
pa-5580
Pa 560
pa-560
Pa 7500
pa-7500
Pa 7500 Dpc A
pa-7500-dpc-a

CVEs (371)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a pr...Show more
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.Show less
1Paloaltonetworks
1Cortex Xsoar
Jun 17, 2026
Nov 8, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the atta...Show more
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Sep 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 12, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system...Show more
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jun 14, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal use...Show more
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link. Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 10, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execu...Show more
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed. Show less
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Apr 12, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Apr 12, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
2Fedoraproject
Paloaltonetworks
2Fedora
Pan Os
Jun 17, 2026
Apr 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and syst...Show more
A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of PAN-OS software.Show less
2Fedoraproject
Paloaltonetworks
2Cortex Xsoar
Fedora
Jun 17, 2026
Feb 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Feb 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Feb 8, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then...Show more
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.Show less
1Paloaltonetworks
1Cortex Xsoar
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with...Show more
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Oct 12, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PA...Show more
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Sep 14, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Aug 10, 2022
N/A· v4
8.6 HIGH· v3
N/A· v2
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Netwo...Show more
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.Show less
1Paloaltonetworks
1Cortex Xsoar
Jun 17, 2026
May 11, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in...Show more
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue impacts: All versions of Cortex XSOAR 6.1; All versions of Cortex XSOAR 6.2; All versions of Cortex XSOAR 6.5; Cortex XSOAR 6.6 versions earlier than Cortex XSOAR 6.6.0 build 6.6.0.2585049.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
May 11, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such...Show more
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version.Show less