← Back

Paloaltonetworks

paloaltonetworks

371 CVEs • 125 products

Products (125)

Click to collapse
Toggle
Pan Os
pan-os
Globalprotect
globalprotect
Expedition
expedition
Cortex Xsoar
cortex_xsoar
Prisma Access
prisma_access
Prisma Cloud
prisma_cloud
Traps
traps
Secdo
secdo
Prisma Sd Wan
prisma_sd-wan
Netconnect
netconnect
Demisto
demisto
Minemeld
minemeld
Twistlock
twistlock
Vm Series
vm-series
Cortex Xsiam
cortex_xsiam
Cloud Ngfw
cloud_ngfw
Broker Vm
broker_vm
Pa 7050
pa-7050
Pa 7080
pa-7080
Pa 200
pa-200
Pa 2020
pa-2020
Pa 2050
pa-2050
Pa 220
pa-220
Pa 3020
pa-3020
Pa 3050
pa-3050
Pa 3060
pa-3060
Pa 3220
pa-3220
Pa 3250
pa-3250
Pa 3260
pa-3260
Pa 500
pa-500
Pa 5200
pa-5200
Pa 800
pa-800
Pa 5410
pa-5410
Pa 5420
pa-5420
Pa 5430
pa-5430
Pa 5440
pa-5440
Pa 5445
pa-5445
Pa 1410
pa-1410
Pa 1420
pa-1420
Pa 3410
pa-3410
Pa 3420
pa-3420
Pa 3430
pa-3430
Pa 3440
pa-3440
Pa 410
pa-410
Pa 410r
pa-410r
Pa 410r 5g
pa-410r-5g
Pa 415
pa-415
Pa 415 5g
pa-415-5g
Pa 440
pa-440
Pa 445
pa-445
Pa 450
pa-450
Pa 450r
pa-450r
Pa 450r 5g
pa-450r-5g
Pa 455
pa-455
Pa 455 5g
pa-455-5g
Pa 455r 5g
pa-455r-5g
Pa 460
pa-460
Pa 501
pa-501
Pa 505
pa-505
Pa 510
pa-510
Pa 520
pa-520
Pa 540
pa-540
Pa 545 Poe
pa-545-poe
Pa 5450
pa-5450
Pa 550
pa-550
Pa 5540
pa-5540
Pa 555 Poe
pa-555-poe
Pa 5550
pa-5550
Pa 5560
pa-5560
Pa 5570
pa-5570
Pa 5580
pa-5580
Pa 560
pa-560
Pa 7500
pa-7500
Pa 7500 Dpc A
pa-7500-dpc-a

CVEs (371)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Idira Endpoint Privilege Manager
Jun 22, 2026
Jun 11, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptograp...Show more
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19Show less
1Paloaltonetworks
2Idira Secrets Manager
Idira Secrets Manager Credential Providers
Jun 22, 2026
Jun 11, 2026
8.4 HIGH· v4
8.1 HIGH· v3
N/A· v2
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage th...Show more
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20Show less
1Paloaltonetworks
1Idira Secrets Manager Edge
Jun 22, 2026
Jun 11, 2026
9.1 CRITICAL· v4
9.1 CRITICAL· v3
N/A· v2
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted...Show more
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20Show less
1Paloaltonetworks
1Idira Endpoint Privilege Manager
Jun 22, 2026
Jun 11, 2026
8.9 HIGH· v4
7.8 HIGH· v3
N/A· v2
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal commu...Show more
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19Show less
1Paloaltonetworks
2Cortex Xsiam Commvaultsecurityiq Marketplace
Cortex Xsoar Commvaultsecurityiq Marketplace
Jul 10, 2026
Jun 10, 2026
8.1 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
1Paloaltonetworks
1Pan Os
Jul 14, 2026
Jun 10, 2026
6.1 MEDIUM· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, t...Show more
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.Show less
1Paloaltonetworks
1Pan Os
Jul 14, 2026
Jun 10, 2026
6.0 MEDIUM· v4
7.2 HIGH· v3
N/A· v2
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges....Show more
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 10, 2026
Jun 10, 2026
5.9 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on W...Show more
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.Show less
1Paloaltonetworks
1Cortex Xsoar
Jul 10, 2026
Jun 10, 2026
4.8 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response...Show more
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.Show less
1Paloaltonetworks
1Pan Os
Jul 14, 2026
Jun 10, 2026
4.6 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts t...Show more
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.Show less
1Paloaltonetworks
1Prisma Access Agent
Jul 13, 2026
Jun 10, 2026
4.4 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Androi...Show more
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.Show less
1Paloaltonetworks
1Globalprotect
Jul 7, 2026
Jun 10, 2026
4.4 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After...Show more
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.Show less
1Paloaltonetworks
1Pan Os
Jul 14, 2026
Jun 10, 2026
1.1 LOW· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-O...Show more
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.Show less
1Paloaltonetworks
1Prisma Sd Wan
Jul 14, 2026
May 13, 2026
4.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a sp...Show more
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.Show less
2Paloaltonetworks
Siemens
2Pan Os
Ruggedcom Ape1808 Firmware
Jul 14, 2026
May 13, 2026
6.6 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network tr...Show more
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not impacted by these vulnerabilities.Show less
2Paloaltonetworks
Siemens
2Pan Os
Ruggedcom Ape1808 Firmware
Jul 14, 2026
May 13, 2026
6.1 MEDIUM· v4
7.2 HIGH· v3
N/A· v2
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this...Show more
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by these vulnerabilities.Show less
1Paloaltonetworks
1Pan Os
Jul 14, 2026
May 13, 2026
5.0 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and...Show more
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.Show less
2Paloaltonetworks
Siemens
2Pan Os
Ruggedcom Ape1808 Firmware
Jul 14, 2026
May 13, 2026
4.8 MEDIUM· v4
9.1 CRITICAL· v3
N/A· v2
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destin...Show more
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.Show less
2Paloaltonetworks
Siemens
3Pan Os
Prisma AccessRuggedcom Ape1808 Firmware
Jun 17, 2026
May 13, 2026
7.8 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Pano...Show more
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.Show less
2Paloaltonetworks
Siemens
2Pan Os
Ruggedcom Ape1808 Firmware
Jul 14, 2026
May 13, 2026
4.4 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable t...Show more
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability.Show less