imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2020-1994
Medium 4.1

A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlie…

paloaltonetworks pan-os
0.00EPSS
CVE-2024-8688
Medium 4.4

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewa…

paloaltonetworks pan-os
0.00EPSS
CVE-2022-0025
Medium 6.7

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevat…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2026-0234
Critical 9.1

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

paloaltonetworks cortex_xsiam · paloaltonetworks cortex_xsoar
0.00EPSS
CVE-2024-5913
Medium 6.1

An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0285
Medium 4.9

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The sec…

paloaltonetworks pan-os
0.00EPSS
CVE-2022-0015
High 7.8

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR a…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2025-4614
Low 2.7

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.  …

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0269
Medium 5.7

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall …

paloaltonetworks pan-os
0.00EPSS
CVE-2022-0021
Low 3.3

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue imp…

paloaltonetworks globalprotect
0.00EPSS
CVE-2022-0013
Medium 5.0

A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Cortex …

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2021-3038
Medium 5.5

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue…

paloaltonetworks globalprotect
0.00EPSS
CVE-2022-0026
Medium 6.7

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevat…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2026-0244
High 8.1

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

paloaltonetworks prisma_sd-wan
0.00EPSS
CVE-2023-0001
Medium 6.0

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool comman…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2026-0283
High 7.2

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, …

paloaltonetworks pan-os
0.00EPSS
CVE-2024-9469
Medium 5.5

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then t…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2024-5915
High 7.8

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-2032
High 7.0

A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: Gl…

paloaltonetworks globalprotect
0.00EPSS
CVE-2022-0029
Medium 5.5

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2022-0016
High 7.4

An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect Befo…

paloaltonetworks globalprotect
0.00EPSS
CVE-2021-3032
Medium 4.4

An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged inform…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0270
High 7.5

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) …

paloaltonetworks cortex_xsoar
0.00EPSS
CVE-2026-0280
High 7.2

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cl…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0248
Medium 5.9

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Cer…

paloaltonetworks prisma_access_agent
0.00EPSS