Total
6 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-0289 | 1 Paloaltonetworks | 1 Prisma Browser | 2026-09-09 | N/A | 6.5 MEDIUM |
| A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | |||||
| CVE-2026-0290 | 1 Paloaltonetworks | 1 Prisma Browser | 2026-09-09 | N/A | 5.5 MEDIUM |
| An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | |||||
| CVE-2026-0275 | 2 Apple, Paloaltonetworks | 2 Macos, Prisma Browser | 2026-07-14 | N/A | 6.7 MEDIUM |
| A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS. | |||||
| CVE-2026-0235 | 1 Paloaltonetworks | 1 Prisma Browser | 2026-07-14 | N/A | 4.7 MEDIUM |
| A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. | |||||
| CVE-2026-0237 | 2 Apple, Paloaltonetworks | 2 Macos, Prisma Browser | 2026-07-14 | N/A | 7.8 HIGH |
| An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls. | |||||
| CVE-2026-0236 | 2 Apple, Paloaltonetworks | 2 Macos, Prisma Browser | 2026-07-13 | N/A | 7.8 HIGH |
| A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser. | |||||
