Palo Alto Networks threat watch

PSIRT advisories for PAN-OS, Prisma, Cortex XDR/XSIAM/XSOAR, and adjacent managed security products.

Watch items

Recent Palo Alto Networks watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (PAN-SA-2026-0010)

critical
activeVendor advisory

Palo Alto Networks incorporated the following Chromium security fixes into our products: * https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent (CVE-2026-0288)

critical
activeVendor advisoryCVE-2026-0288

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.). Panorama is not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface (CVE-2026-0285)

high
activeVendor advisoryCVE-2026-0285

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431). Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) (CVE-2026-0283)

high
activeVendor advisoryCVE-2026-0283

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing (CVE-2026-0287)

high
activeVendor advisoryCVE-2026-0287

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) (CVE-2026-0284)

high
activeVendor advisoryCVE-2026-0284

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows (CVE-2026-0278)

high
activeVendor advisoryCVE-2026-0278

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.

Jul 8, 2026, 11:00 AMOfficial source

Prisma Access Agent: Improper Certificate Validation on iOS (CVE-2026-0277)

high
activeVendor advisoryCVE-2026-0277

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Authenticated Command Injection in CLI (CVE-2026-0286)

high
activeVendor advisoryCVE-2026-0286

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities (CVE-2026-0279)

medium
watchVendor advisoryCVE-2026-0279

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431). This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability (CVE-2026-0276)

medium
watchVendor advisoryCVE-2026-0276

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: Information Disclosure Vulnerability in Management Web Interface (CVE-2026-0281)

medium
watchVendor advisoryCVE-2026-0281

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431). This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: IPv6 Firewall Policy Bypass (CVE-2026-0280)

medium
watchVendor advisoryCVE-2026-0280

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

PAN-OS: File Deletion Vulnerability in Management Web Interface (CVE-2026-0282)

medium
watchVendor advisoryCVE-2026-0282

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431). This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability.

Jul 8, 2026, 11:00 AMOfficial source

idira privileged access manager vault vulnerability (CVE-2026-45169)

HIGH
watchNVDCVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17

Jun 12, 2026, 12:16 AMOfficial source

idira secrets manager edge vulnerability (CVE-2026-45177)

CRITICAL
watchNVDCVE-2026-45177

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20

Jun 11, 2026, 2:16 PMOfficial source

Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration (CVE-2026-0274)

critical
activeVendor advisoryCVE-2026-0274

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

Jun 10, 2026, 11:00 AMOfficial source

Chromium: Monthly Vulnerability Update (June 2026) (PAN-SA-2026-0008)

critical
activeVendor advisory

Palo Alto Networks incorporated the following Chromium security fixes into our products: * https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html

Jun 10, 2026, 11:00 AMOfficial source

Prisma Access Agent: Local Privilege Escalation by Authorized Users (CVE-2026-0271)

high
activeVendor advisoryCVE-2026-0271

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

Jun 10, 2026, 11:00 AMOfficial source

Cortex XSOAR: Path Traversal Vulnerability (CVE-2026-0270)

high
activeVendor advisoryCVE-2026-0270

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

Jun 10, 2026, 11:00 AMOfficial source

Vendor watch hub

What this page covers

The Palo Alto Networkswatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Palo Alto Networks activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

113

Active

66

Featured

74

Unique CVEs

18

Most recent entry

Jul 8, 2026, 11:00 AM

Feed refreshes daily · 5:15 a.m. Central

Sources·Palo Alto Networks security advisories JSON, CISA KEV, and NVD

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Related vendors

Other security vendors in the radar

Vendor watch FAQ

Common questions

What is the Palo Alto Networks threat watch page?

It is the Palo Alto Networks-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Palo Alto Networks watch page?

Use it to confirm whether current Palo Alto Networks issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Palo Alto Networks security issues?

Yes. ITECS can help map Palo Alto Networks advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.