Paloaltonetworks
paloaltonetworks
371 CVEs • 125 products
Products (125)
Click to collapseToggle
Products (125)
Click to collapse
CVEs (371)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Paloaltonetworks 1Idira Endpoint Privilege Manager Jun 22, 2026 Jun 11, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptograp...Show more |
1Paloaltonetworks 2Idira Secrets Manager Idira Secrets Manager Credential ProvidersJun 22, 2026 Jun 11, 2026 8.4 HIGH· v4 8.1 HIGH· v3 N/A· v2 Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage th...Show more |
1Paloaltonetworks 1Idira Secrets Manager Edge Jun 22, 2026 Jun 11, 2026 9.1 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted...Show more |
1Paloaltonetworks 1Idira Endpoint Privilege Manager Jun 22, 2026 Jun 11, 2026 8.9 HIGH· v4 7.8 HIGH· v3 N/A· v2 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal commu...Show more |
1Paloaltonetworks 2Cortex Xsiam Commvaultsecurityiq Marketplace Cortex Xsoar Commvaultsecurityiq MarketplaceJul 10, 2026 Jun 10, 2026 8.1 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources. |
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, t...Show more |
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges....Show more |
1Paloaltonetworks 1Prisma Access Agent Jul 10, 2026 Jun 10, 2026 5.9 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on W...Show more |
1Paloaltonetworks 1Cortex Xsoar Jul 10, 2026 Jun 10, 2026 4.8 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response...Show more |
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts t...Show more |
1Paloaltonetworks 1Prisma Access Agent Jul 13, 2026 Jun 10, 2026 4.4 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Androi...Show more |
1Paloaltonetworks 1Globalprotect Jul 7, 2026 Jun 10, 2026 4.4 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After...Show more |
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-O...Show more |
1Paloaltonetworks 1Prisma Sd Wan Jul 14, 2026 May 13, 2026 4.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a sp...Show more |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJul 14, 2026 May 13, 2026 6.6 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network tr...Show more |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJul 14, 2026 May 13, 2026 6.1 MEDIUM· v4 7.2 HIGH· v3 N/A· v2 Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this...Show more |
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and...Show more |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJul 14, 2026 May 13, 2026 4.8 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destin...Show more |
2Paloaltonetworks Siemens3Pan Os Prisma AccessRuggedcom Ape1808 FirmwareJun 17, 2026 May 13, 2026 7.8 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Pano...Show more |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJul 14, 2026 May 13, 2026 4.4 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable t...Show more |