CVE-2026-0232: Cortex XDR Agent: Local Administrator can disable the agent on Windows (Severity: MEDIUM)
Published Apr 8, 2026
·Updated
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
Affected Software
9 affected componentsFixes available
Palo Alto Networks Cortex XDR Agent
All of the following
Palo Alto Networks Cortex XDR Agent<9.0.1, =9.0, <8.9.1, =8.9, <8.7.101-CE, =8.7-CE, =8.3-CE, =7.9-CE
9.0.18.9.18.7.101-CE8.3-CE7.9-CE
Microsoft Windows*
All of the following
Any of the following
Palo Alto Networks Cortex XDR Agent>=8.7.0<8.7.101
Palo Alto Networks Cortex XDR Agent=7.9
Palo Alto Networks Cortex XDR Agent=8.3
Palo Alto Networks Cortex XDR Agent=8.9.0
Palo Alto Networks Cortex XDR Agent=9.0.0
Microsoft Windows
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.1Fixed in 8.9.1Fixed in 8.7.101-CEFixed in 8.3-CEFixed in 7.9-CE
Event History
Apr 8, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 13, 2026
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software