Paloaltonetworks
paloaltonetworks
371 CVEs • 125 products
Products (125)
Click to collapseToggle
Products (125)
Click to collapse
CVEs (371)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Paloaltonetworks 1Globalprotect Jul 14, 2026 May 13, 2026 5.9 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables...Show more |
1Paloaltonetworks 1Globalprotect Jul 14, 2026 May 13, 2026 5.2 MEDIUM· v4 8.1 HIGH· v3 N/A· v2 A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. Thi...Show more |
1Paloaltonetworks 1Globalprotect Jul 14, 2026 May 13, 2026 4.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a l...Show more |
1Paloaltonetworks 1Prisma Access Agent Jul 14, 2026 May 13, 2026 6.2 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificat...Show more |
1Paloaltonetworks 1Prisma Access Agent Jul 14, 2026 May 13, 2026 5.9 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations. |
1Paloaltonetworks 1Prisma Access Agent Jul 14, 2026 May 13, 2026 5.9 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT A...Show more |
1Paloaltonetworks 1Prisma Access Agent Jul 14, 2026 May 13, 2026 4.3 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not a...Show more |
1Paloaltonetworks 1Prisma Sd Wan Jul 14, 2026 May 13, 2026 5.2 MEDIUM· v4 8.1 HIGH· v3 N/A· v2 An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller. |
1Paloaltonetworks 1Trust Protection Foundation Jul 13, 2026 May 13, 2026 5.1 MEDIUM· v4 7.2 HIGH· v3 N/A· v2 Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources. |
1Paloaltonetworks 1Trust Protection Foundation Jul 13, 2026 May 13, 2026 4.5 MEDIUM· v4 8.7 HIGH· v3 N/A· v2 An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker...Show more |
1Paloaltonetworks 1Chronosphere Collector Jul 13, 2026 May 13, 2026 4.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information. |
A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields. |
1Paloaltonetworks 1Prisma Browser Jul 13, 2026 May 13, 2026 7.3 HIGH· v4 7.8 HIGH· v3 N/A· v2 A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple...Show more |
1Paloaltonetworks 1Prisma Browser Jul 14, 2026 May 13, 2026 5.8 MEDIUM· v4 4.7 MEDIUM· v3 N/A· v2 A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJul 14, 2026 May 13, 2026 7.2 HIGH· v4 8.1 HIGH· v3 N/A· v2 An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled....Show more |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJul 14, 2026 May 13, 2026 7.2 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN...Show more |
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause...Show more |
1Paloaltonetworks 1Prisma Browser Jul 14, 2026 May 13, 2026 7.3 HIGH· v4 7.8 HIGH· v3 N/A· v2 An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user...Show more |
2Paloaltonetworks Siemens2Pan Os Ruggedcom Ape1808 FirmwareJun 17, 2026 May 6, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges o...Show more |
1Paloaltonetworks 2Cortex Xsiam Cortex XsoarJul 7, 2026 Apr 13, 2026 7.2 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protecte...Show more |