58.476 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Palo Alto vulnerabilities
383 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-0295 | HIGH 7.0 | paloaltonetworks globalprotect A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected. | 0.1% | — |
| CVE-2024-5905 | MED 4.4 | paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechani | 0.1% | — |
| CVE-2026-0268 | MED 4.4 | paloaltonetworks prisma_access_agent A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | 0.1% | — |
| CVE-2026-0238 | LOW 3.2 | paloaltonetworks broker_vm A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields. | 0.1% | — |
| CVE-2026-0267 | MED 5.5 | paloaltonetworks globalprotect An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can per | 0.1% | — |
| CVE-2026-0293 | MED 6.0 | paloaltonetworks prisma_access_agent A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, | 0.1% | — |
| CVE-2026-0271 | HIGH 7.8 | paloaltonetworks prisma_access_agent A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS | 0.1% | — |
| CVE-2026-0235 | MED 4.7 | paloaltonetworks prisma_browser A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. | 0.1% | — |
| CVE-2026-0291 | MED 4.4 | paloaltonetworks prisma_access_agent An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prism | 0.1% | — |
| CVE-2026-0249 | MED 6.5 | paloaltonetworks globalprotect Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system | 0.1% | — |
| CVE-2023-0006 | MED 6.3 | paloaltonetworks globalprotect A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition. | 0.1% | — |
| CVE-2026-0294 | HIGH 7.8 | paloaltonetworks prisma_access_agent A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affec | 0.1% | — |
| CVE-2022-0031 | MED 6.7 | paloaltonetworks cortex_xsoar A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges. | 0.1% | — |
| CVE-2026-0290 | MED 5.5 | paloaltonetworks prisma_browser An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | 0.1% | — |
| CVE-2022-0022 | MED 4.1 | paloaltonetworks pan-os Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on acco | 0.1% | — |
| CVE-2026-0292 | MED 6.0 | paloaltonetworks prisma_access_agent An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The | 0.1% | — |
| CVE-2024-5907 | HIGH 7.0 | paloaltonetworks cortex_xdr_agent A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, | 0.1% | — |
| CVE-2025-0135 | LOW 3.3 | paloaltonetworks globalprotect An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and Glob | 0.1% | — |
| CVE-2026-0296 | HIGH 7.4 | paloaltonetworks globalprotect Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The Global | 0.1% | — |
| CVE-2026-0266 | MED 4.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series fi | 0.1% | — |
| CVE-2026-0276 | HIGH 7.8 | paloaltonetworks cortex_xdr_broker_vm A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. | 0.1% | — |
| CVE-2026-0245 | MED 5.5 | paloaltonetworks prisma_access_agent Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected. | 0.1% | — |
| CVE-2026-0232 | MED 4.4 | paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | 0.1% | — |
| CVE-2026-0246 | HIGH 7.8 | paloaltonetworks prisma_access_agent A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows | 0.1% | — |
| CVE-2026-0237 | HIGH 7.8 | paloaltonetworks prisma_browser An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication ch | 0.1% | — |