CVE-2026-0230: Cortex XDR Agent: Local Administrator can disable the agent on macOS (Severity: MEDIUM)
Published Mar 11, 2026
·Updated
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
Affected Software
2 affected componentsFixes available
All of the following
Palo Alto Networks Cortex XDR Agent<8.7.101-CE, =8.7-CE, <8.3.102-CE, =8.3-CE
8.7.101-CE8.3.102-CE
Apple macOS*
Remediation
Information
This issue is fixed in Cortex XDR Agent 8.9.0, Cortex XDR Agent 8.7.101-CE, Cortex XDR Agent 8.3.102-CE, and all later Cortex XDR Agent versions.
Event History
Mar 11, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-0230?
The severity of CVE-2026-0230 is classified as MEDIUM.
2
How do I fix CVE-2026-0230?
To fix CVE-2026-0230, update the Cortex XDR Agent to the latest available version.
3
Who is affected by CVE-2026-0230?
CVE-2026-0230 affects the Cortex XDR Agent versions 8.3-CE and 8.7-CE on macOS.
4
What is the impact of CVE-2026-0230?
The impact of CVE-2026-0230 allows a local administrator to disable the Cortex XDR Agent, potentially enabling malware exploitation.
5
Is macOS vulnerable to CVE-2026-0230?
No, macOS itself is not vulnerable, but the Cortex XDR Agent running on it is susceptible based on its configuration.