imPC@ndo EN

Vulnerabilità Palo Alto

371 CVE

CVE-2024-5907
Alta 7.0

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, …

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2026-0266
Media 4.8

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series fi…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-45175
Alta 7.8

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumst…

paloaltonetworks idira_endpoint_privilege_manager
0.00EPSS
CVE-2022-0022
Media 4.1

Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on acco…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-45174
Alta 7.8

Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19

paloaltonetworks idira_endpoint_privilege_manager
0.00EPSS
CVE-2026-45176
Alta 7.8

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Un…

paloaltonetworks idira_endpoint_privilege_manager
0.00EPSS
CVE-2025-0135
Bassa 3.3

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and Glob…

paloaltonetworks globalprotect
0.00EPSS
CVE-2022-0031
Media 6.7

A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.

paloaltonetworks cortex_xsoar
0.00EPSS
CVE-2026-0275
Media 6.7

A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Bro…

paloaltonetworks prisma_browser
0.00EPSS
CVE-2026-0277
Media 5.9

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not aff…

paloaltonetworks prisma_access_agent
0.00EPSS
CVE-2026-0249
Media 6.5

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system…

paloaltonetworks globalprotect
0.00EPSS
CVE-2023-0006
Media 6.3

A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.

paloaltonetworks globalprotect
0.00EPSS
CVE-2026-0235
Media 4.7

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

paloaltonetworks prisma_browser
0.00EPSS
CVE-2026-0271
Alta 7.8

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS…

paloaltonetworks prisma_access_agent
0.00EPSS
CVE-2026-0278
Alta 7.8

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.

paloaltonetworks prisma_access_agent
0.00EPSS
CVE-2026-45170
Alta 8.8

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

paloaltonetworks idira_privilege_cloud_connector
0.00EPSS
CVE-2026-0267
Media 5.5

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can per…

paloaltonetworks globalprotect
0.00EPSS
CVE-2026-0276
Alta 7.8

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.

paloaltonetworks cortex_xdr_broker_vm
0.00EPSS
CVE-2026-0238
Bassa 3.2

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

paloaltonetworks broker_vm
0.00EPSS
CVE-2026-0268
Media 4.4

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

paloaltonetworks prisma_access_agent
0.00EPSS
CVE-2024-5905
Media 4.4

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechani…

paloaltonetworks cortex_xdr_agent
0.00EPSS