CVE-2026-0277: Prisma Access Agent: Improper Certificate Validation on iOS (Severity: MEDIUM)
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic.
The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.1 - Upgrade
Upgrade
Prisma Access Agent (iOS)to a version that resolves this vulnerability.Fixed in 26.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0277?
CVE-2026-0277 has a high severity rating of 8.7.
How does CVE-2026-0277 affect users?
CVE-2026-0277 allows attackers to perform a man-in-the-middle attack, potentially intercepting VPN traffic on iOS devices.
What versions of the Prisma Access Agent are affected by CVE-2026-0277?
Only the Prisma Access Agent for iOS is affected by CVE-2026-0277; other platforms are not impacted.
How can I mitigate the risks of CVE-2026-0277?
To mitigate CVE-2026-0277, ensure that you update the Prisma Access Agent to the latest version that addresses this vulnerability.
What is the primary vulnerability found in CVE-2026-0277?
CVE-2026-0277 involves improper certificate validation, which can lead to security vulnerabilities.