58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Palo Alto vulnerabilities
383 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-0301 | HIGH 7.5 | paloaltonetworks cloud_ngfw An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability. | 0.3% | — |
| CVE-2020-2004 | MED 6.8 | paloaltonetworks globalprotect Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows. For this issue to occur all o | 0.3% | — |
| CVE-2020-1984 | HIGH 7.8 | paloaltonetworks secdo Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. Th | 0.3% | — |
| CVE-2026-0297 | HIGH 8.1 | paloaltonetworks globalprotect A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileg | 0.3% | — |
| CVE-2019-17436 | HIGH 7.1 | paloaltonetworks globalprotect A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earlier, that can allow non-root users to overwrite root files on the file system. | 0.3% | — |
| CVE-2020-2020 | MED 5.5 | paloaltonetworks cortex_xdr_agent An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition | 0.3% | — |
| CVE-2020-1978 | MED 5.8 | paloaltonetworks pan-os TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials ass | 0.3% | — |
| CVE-2020-1987 | LOW 3.9 | paloaltonetworks globalprotect An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Palo Alto Net | 0.3% | — |
| CVE-2023-0002 | MED 5.5 | paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent. | 0.3% | — |
| CVE-2024-9471 | MED 4.7 | paloaltonetworks pan-os A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administra | 0.3% | — |
| CVE-2019-17435 | MED 5.5 | paloaltonetworks globalprotect A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.12 and earlier, in which the auto-update feature can allow for modification of a GlobalProtect Agent MSI install | 0.3% | — |
| CVE-2026-0282 | MED 6.5 | paloaltonetworks pan-os A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by rest | 0.3% | — |
| CVE-2024-9473 | HIGH 7.8 | paloaltonetworks globalprotect A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered b | 0.3% | — |
| CVE-2026-0274 | CRIT 9.1 | paloaltonetworks cortex_xsiam_commvaultsecurityiq_marketplace An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources. | 0.3% | — |
| CVE-2026-0281 | HIGH 7.1 | paloaltonetworks pan-os An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious l | 0.3% | — |
| CVE-2020-1976 | MED 4.7 | paloaltonetworks globalprotect A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5. | 0.3% | — |
| CVE-2020-1991 | HIGH 7.8 | paloaltonetworks traps An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on | 0.3% | — |
| CVE-2022-0017 | HIGH 7.0 | paloaltonetworks globalprotect An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privilege | 0.3% | — |
| CVE-2019-1573 | LOW 2.5 | paloaltonetworks globalprotect GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session token | 0.3% | — |
| CVE-2020-1989 | HIGH 7.0 | paloaltonetworks globalprotect An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Al | 0.3% | — |
| CVE-2023-0005 | MED 4.1 | paloaltonetworks pan-os A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys. | 0.3% | — |
| CVE-2026-0272 | HIGH 7.2 | paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is | 0.3% | — |
| CVE-2020-1986 | MED 5.5 | paloaltonetworks secdo Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS disk (C:\) to cause a system crash on every login. This issue affects all versions Secdo for Windows. | 0.3% | — |
| CVE-2025-4614 | LOW 2.7 | paloaltonetworks pan-os An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked. | 0.3% | — |
| CVE-2020-1985 | HIGH 7.8 | paloaltonetworks secdo Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges. This issue affects all versions Secdo for Windows. | 0.3% | — |