Vendor
Palo Alto Networks vulnerabilities
41 advisories tracked, 15 exploited in the wild according to CISA, 28 published in 2026.
Data refreshed 10 Oct 2026
Patch now
Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).
CVE-2026-0257PAN-OS
GlobalProtect Authentication Bypass VulnerabilitiesCVE-2026-0300PAN-OS
Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalCVE-2025-0111PAN-OS
Authenticated File Read Vulnerability in the Management Web InterfaceCVE-2025-0108PAN-OS
Authentication Bypass in the Management Web InterfaceCVE-2024-3393PAN-OS
Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted PacketCVE-2024-9474PAN-OS
Privilege Escalation (PE) Vulnerability in the Web Management Interface
Show all 10Show fewer
CVE-2024-0012PAN-OS
Authentication Bypass in the Management Web InterfaceCVE-2024-9465Expedition
Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall CredentialsCVE-2024-9463Expedition
Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall CredentialsCVE-2024-5910Expedition
Missing Authentication Leads to Admin Account Takeover
Products covered
Select a product to see only its advisories.
- PAN-OSNGFW, Panorama and the GlobalProtect portal and gateway23 tracked
- GlobalProtect AppThe VPN client on Windows, macOS, Linux and mobile8 tracked
- Prisma AccessSASE and SSE service and its endpoint agent14 tracked
- Cortex XDREDR agent, Broker VM and XSIAM components1 tracked
- ExpeditionThe configuration migration tool3 tracked
All tracked advisories
Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.
| Published | CVE | Product | Issue | Severity | EPSS | Exploited |
|---|---|---|---|---|---|---|
| CVE-2026-0310 | PAN-OS | Buffer Overflow Vulnerability via XML Processing | HIGH 9.2 | 0.37% | – | |
| CVE-2026-0309 | PAN-OS | Authenticated Command Injection in CLI with Luna HSM Configuration | MEDIUM 7.1 | 0.45% | – | |
| CVE-2026-0308 | PAN-OS | Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface | LOW 4.8 | 0.27% | – | |
| CVE-2026-0307 | GlobalProtect App | Local Privilege Escalation Vulnerabilities | MEDIUM 8.5 | 0.10% | – | |
| CVE-2026-0306 | Prisma Access | EndPoint DLP Bypass Vulnerability on Windows | MEDIUM 8.4 | 0.10% | – | |
| CVE-2026-0305 | Prisma Access | Information Disclosure Vulnerability on Linux | MEDIUM 6.8 | 0.10% | – | |
| CVE-2026-0304 | Cortex XDR | Privilege Escalation Vulnerability | MEDIUM 7.5 | 0.22% | – | |
| CVE-2026-0301 | PAN-OS | Information Disclosure Vulnerability in URL Filtering | LOW 6.3 | 0.32% | – | |
| CVE-2026-0299 | GlobalProtect App | Local Privilege Escalation Vulnerabilities | MEDIUM 8.5 | 0.20% | – | |
| CVE-2026-0298 | GlobalProtect App | Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) | MEDIUM 7.7 | 0.33% | – | |
| CVE-2026-0297 | GlobalProtect App | Buffer Overflow Vulnerability during UDP Tunnel Handshake | MEDIUM 7.7 | 0.31% | – | |
| CVE-2026-0296 | GlobalProtect App | Improper Certificate Validation Bypass Vulnerability | MEDIUM 7.4 | 0.14% | – | |
| CVE-2026-0295 | GlobalProtect App | Local Privilege Escalation via Race Condition on macOS | MEDIUM 7.2 | 0.07% | – | |
| CVE-2026-0294 | Prisma Access | Local Privilege Escalation | MEDIUM 8.5 | 0.11% | – | |
| CVE-2026-0293 | Prisma Access | Anti-Tamper Protection Bypass on Windows | MEDIUM 8.3 | 0.11% | – | |
| CVE-2026-0292 | Prisma Access | Local Security Inspection Bypass Vulnerability on Windows | LOW 6.1 | 0.13% | – | |
| CVE-2026-0291 | Prisma Access | Authenticated Limited File Deletion on Linux | LOW 4.8 | 0.11% | – | |
| CVE-2026-0288 | PAN-OS | Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent | HIGH 9.2 | 0.83% | – | |
| CVE-2026-0287 | PAN-OS | Denial of Service Vulnerabilities in Network Traffic Processing | MEDIUM 8.7 | 0.62% | – | |
| CVE-2026-0286 | PAN-OS | Authenticated Command Injection in CLI | MEDIUM 8.5 | 1.7% | – | |
| CVE-2026-0285 | PAN-OS | Server-Side Request Forgery Vulnerability in Management Web Interface | MEDIUM 7 | 0.43% | – | |
| CVE-2026-0279 | PAN-OS | Multiple Cross-Site Scripting (XSS) Vulnerabilities | LOW 5.3 | 0.75% | – | |
| CVE-2026-0280 | PAN-OS | IPv6 Firewall Policy Bypass | LOW 6.3 | 0.34% | – | |
| CVE-2026-0281 | PAN-OS | Information Disclosure Vulnerability in Management Web Interface | LOW 5.9 | 0.28% | – | |
| CVE-2026-0257Full analysis | PAN-OS | GlobalProtect Authentication Bypass Vulnerabilities | HIGH 7.8 | 97% | Yes · ransomware | |
| CVE-2026-0250 | GlobalProtect App | Buffer Overflow Vulnerability during connection to Portal or Gateway | MEDIUM 7.7 | 0.39% | – | |
| CVE-2026-0251 | GlobalProtect App | Local Privilege Escalation Vulnerabilities | HIGH 8.5 | 0.18% | – | |
| CVE-2026-0300Full analysis | PAN-OS | Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | CRITICAL 9.3 | 32% | Yes | |
| CVE-2025-0111 | PAN-OS | Authenticated File Read Vulnerability in the Management Web Interface | HIGH 7.1 | 2.0% | Yes | |
| CVE-2025-0108Full analysis | PAN-OS | Authentication Bypass in the Management Web Interface | HIGH 8.8 | 98% | Yes | |
| CVE-2024-3393 | PAN-OS | Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | HIGH 8.7 | 29% | Yes | |
| CVE-2024-9474Full analysis | PAN-OS | Privilege Escalation (PE) Vulnerability in the Web Management Interface | MEDIUM 6.9 | 95% | Yes · ransomware | |
| CVE-2024-0012Full analysis | PAN-OS | Authentication Bypass in the Management Web Interface | CRITICAL 9.3 | 100% | Yes · ransomware | |
| CVE-2024-9465 | Expedition | Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials | CRITICAL 9.9 | 100% | Yes | |
| CVE-2024-9463 | Expedition | Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials | CRITICAL 9.9 | 99% | Yes | |
| CVE-2024-5910 | Expedition | Missing Authentication Leads to Admin Account Takeover | CRITICAL 9.3 | 92% | Yes | |
| CVE-2024-3400Full analysis | PAN-OS | Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | CRITICAL 10 | 100% | Yes · ransomware | |
| CVE-2022-0028 | PAN-OS | Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering | HIGH 8.6 | 2.5% | Yes | |
| CVE-2020-2021 | PAN-OS | Authentication Bypass in SAML Authentication | CRITICAL 10 | 4.4% | Yes · ransomware | |
| CVE-2019-1579 | PAN-OS | Remote Code Execution in GlobalProtect Portal/Gateway Interface | HIGH 8.1 | 46% | Yes · ransomware | |
| CVE-2017-15944 | PAN-OS | Vulnerability in PAN-OS and Panorama on Management Interface | CRITICAL 9.8 | 98% | Yes |
Sources: Palo Alto Networks security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.