Filtered by vendor Paloaltonetworks
Subscribe
Total
383 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-0240 | 1 Paloaltonetworks | 1 Trust Protection Foundation | 2026-07-13 | N/A | 8.7 HIGH |
| An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings. | |||||
| CVE-2026-0241 | 1 Paloaltonetworks | 1 Trust Protection Foundation | 2026-07-13 | N/A | 7.2 HIGH |
| Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources. | |||||
| CVE-2026-0232 | 2 Microsoft, Paloaltonetworks | 2 Windows, Cortex Xdr Agent | 2026-07-07 | N/A | 4.4 MEDIUM |
| A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | |||||
| CVE-2026-0233 | 2 Microsoft, Paloaltonetworks | 2 Windows, Autonomous Digital Experience Manager | 2026-07-07 | N/A | 8.8 HIGH |
| A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |||||
| CVE-2026-0234 | 1 Paloaltonetworks | 2 Cortex Xsiam, Cortex Xsoar | 2026-07-07 | N/A | 9.1 CRITICAL |
| An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. | |||||
| CVE-2026-45169 | 1 Paloaltonetworks | 1 Idira Privileged Access Manager Vault | 2026-07-07 | N/A | 8.6 HIGH |
| Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17 | |||||
| CVE-2026-45170 | 1 Paloaltonetworks | 1 Idira Privilege Cloud Connector | 2026-06-23 | N/A | 8.8 HIGH |
| Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | |||||
| CVE-2026-45172 | 1 Paloaltonetworks | 1 Idira Privileged Session Manager For Ssh | 2026-06-23 | N/A | 8.8 HIGH |
| Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 | |||||
| CVE-2026-45171 | 1 Paloaltonetworks | 1 Idira Privileged Session Manager | 2026-06-23 | N/A | 8.8 HIGH |
| Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18 | |||||
| CVE-2026-45174 | 2 Linux, Paloaltonetworks | 2 Linux Kernel, Idira Endpoint Privilege Manager | 2026-06-22 | N/A | 7.8 HIGH |
| Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | |||||
| CVE-2026-45175 | 4 Apple, Linux, Microsoft and 1 more | 4 Macos, Linux Kernel, Windows and 1 more | 2026-06-22 | N/A | 7.8 HIGH |
| Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19 | |||||
| CVE-2026-45176 | 4 Apple, Linux, Microsoft and 1 more | 4 Macos, Linux Kernel, Windows and 1 more | 2026-06-22 | N/A | 7.8 HIGH |
| Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19 | |||||
| CVE-2026-45173 | 4 Google, Microsoft, Mozilla and 1 more | 4 Chrome, Edge Chromium, Firefox and 1 more | 2026-06-22 | N/A | 6.5 MEDIUM |
| Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21 | |||||
| CVE-2026-45178 | 1 Paloaltonetworks | 2 Idira Secrets Manager, Idira Secrets Manager Credential Providers | 2026-06-22 | N/A | 8.1 HIGH |
| Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20 | |||||
| CVE-2026-45177 | 1 Paloaltonetworks | 1 Idira Secrets Manager Edge | 2026-06-22 | N/A | 9.1 CRITICAL |
| Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20 | |||||
| CVE-2026-0300 | 2 Paloaltonetworks, Siemens | 50 Pa-1410, Pa-1420, Pa-3410 and 47 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability. | |||||
| CVE-2026-0257 | 2 Paloaltonetworks, Siemens | 4 Pan-os, Prisma Access, Ruggedcom Ape1808 and 1 more | 2026-06-17 | N/A | 9.1 CRITICAL |
| Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | |||||
| CVE-2026-0227 | 1 Paloaltonetworks | 2 Pan-os, Prisma Access | 2026-06-17 | N/A | 7.5 HIGH |
| A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. | |||||
| CVE-2025-4615 | 1 Paloaltonetworks | 1 Pan-os | 2026-06-17 | N/A | 7.2 HIGH |
| An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability. | |||||
| CVE-2025-4614 | 1 Paloaltonetworks | 1 Pan-os | 2026-06-17 | N/A | 2.7 LOW |
| An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability. | |||||
