Where
-Infinity
0

Vendor Risk Score

See how palo alto networks compares to other vendors in security performance

View Risk Score →

Software

palo alto networks pan-os
89
palo alto networks prisma access
64
palo alto networks cloud ngfw
62
palo alto networks globalprotect
17
palo alto networks globalprotect uwp app
16
palo alto networks globalprotect app
15
palo alto networks prisma access agent
14
palo alto networks prisma browser
14
palo alto networks expedition
11
palo alto networks panorama
10
palo alto networks globalprotect macos
9
palo alto networks globalprotect windows
8
palo alto networks cortex xdr agent
6
palo alto networks cortex xdr
5
palo alto networks cortex xdr broker vm
5
palo alto networks globalprotect linux
5
palo alto networks pa-5440
5
palo alto networks prisma browser
5
palo alto networks prisma sd-wan ion
5
palo alto networks cortex xsoar
4
palo alto networks firewalls
3
palo alto networks globalprotect android
3
palo alto networks pa-5410
3
palo alto networks pa-5420
3
palo alto networks pa-5430
3
palo alto networks pa-5445
3
palo alto networks prisma sd-wan
3
palo alto networks trust protection foundation
3
palo alto networks checkov by prisma cloud
2
palo alto networks cortex xsiam
2
palo alto networks pa-series
2
palo alto networks pan-os (globalprotect)
2
palo alto networks pan-os (pa-series)
2
palo alto networks pan-os (vm-series)
2
palo alto networks pan-os globalprotect
2
palo alto networks pan-os user-id authentication portal
2
palo alto networks vm-series
2
palo alto networks autonomous digital experience manager
1
palo alto networks broker vm
1
palo alto networks chronosphere chronocollector
1
palo alto networks cn-series
1
palo alto networks cortex xdr microsoft 365 defender pack
1
palo alto networks cortex xsiam commvaultsecurityiq integration
1
palo alto networks cortex xsiam commvaultsecurityiq marketplace
1
palo alto networks cortex xsiam microsoft teams marketplace
1
palo alto networks cortex xsoar commvaultsecurityiq integration
1
palo alto networks cortex xsoar commvaultsecurityiq marketplace
1
palo alto networks cortex xsoar microsoft teams marketplace
1
palo alto networks firewall
1
palo alto networks global protect uwp app
1
Severity
10
EPSS
95.36%
Command Injection, Input Validation
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

1 / 2
First published (updated )
Severity
9.9
EPSS
96.12%
Command Injection, OS Command Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

1 / 2
Source: NVD
First published (updated )
Severity
9.9
OS Command Injection, XSS, SQL Injection
AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Amber

Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system. Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

These issues do not affect the firewalls, Panorama, Prisma Access, or Cloud NGFW.

Remedy

Ensure networks access to Expedition is restricted to authorized users, hosts, or networks. If Expedition is not in active use, ensure that Expedition software is shut down. For CVE-2024-9465, you can check for an indicator of compromise with the following command on an Expedition system (replace "root" with your username if you are using a different username): mysql -uroot -p -D pandb -e "SELECT * FROM cronjobs;" If you see any records returned, this indicates a potential compromise. Please note that if no records are returned, the system may still be compromised. This is only intended to indicate a potential compromise, rather than confirm a system has not been compromised. There are no practical indicators of compromise for the remainder of the CVEs in this advisory.

Remedy

The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions. The cleartext file affected by CVE-2024-9466 will be removed automatically during the upgrade. All Expedition usernames, passwords, and API keys should be rotated after upgrading to the fixed version of Expedition. All firewall usernames, passwords, and API keys processed by Expedition should be rotated after updating.
First published (updated )
Severity
9.8
EPSS
0.04%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.

Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
Input Validation, Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

1 / 2
First published (updated )
Severity
9.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .

The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.

1 / 3
Source: NVD
First published (updated )
Severity
9.8
EPSS
0.04%
OS Command Injection, Command Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Green

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

First published (updated )
Severity
9.5
AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:N/R:A/V:D/RE:M/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html

First published (updated )
Severity
9.4
AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:L/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop25.html https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop18.html https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop12.html

Remedy

No workaround or mitigation is available.

Remedy

CVE PRISMA ACCESS BROWSER CVE-2025-0995 133.16.4.99 CVE-2025-0996 133.16.4.99 CVE-2025-0997 133.16.4.99 CVE-2025-0998 133.16.4.99 CVE-2025-0999 133.27.6.127 CVE-2025-1006 133.27.6.127 CVE-2025-1426 133.27.6.127 CVE-2025-1914 134.7.4.44 CVE-2025-1915 134.7.4.44 CVE-2025-1916 134.7.4.44 CVE-2025-1917 134.7.4.44 CVE-2025-1918 134.7.4.44 CVE-2025-1919 134.7.4.44 CVE-2025-1921 134.7.4.44 CVE-2025-1922 134.7.4.44 CVE-2025-1923 134.7.4.44
First published (updated )
Severity
9.4
AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:L/U:Amber

Palo Alto Networks incorporated the following security fixes into Prisma® Access Browser:

https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop25.html https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop21.html https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop19.html https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop10.html https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop25.html

In addition to the above, we also fixed a vulnerability in the Prisma Access browser.

Remedy

No workaround or mitigation is available.

Remedy

CVE PRISMA ACCESS BROWSER CVE-2025-0129 132.83.3017.1 CVE-2025-1920 134.17.2.89 CVE-2025-2135 134.17.2.89 CVE-2025-2136 134.17.2.89 CVE-2025-2137 134.17.2.89 CVE-2025-2476 134.20.7.166 CVE-2025-2783 134.29.5.178
First published (updated )
Severity
9.4
AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:L/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop29.html https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop8.html https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html

Remedy

No workaround or mitigation is available.

Remedy

CVE PRISMA ACCESS BROWSER CVE-2025-0129 132.83.3017.1 CVE-2025-1920 134.17.2.89 CVE-2025-2135 134.17.2.89 CVE-2025-2136 134.17.2.89 CVE-2025-2137 134.17.2.89 CVE-2025-2476 134.20.7.166 CVE-2025-2783 134.29.5.178
First published (updated )
Severity
9.4
AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html

First published (updated )
Severity
9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber

An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.

First published (updated )
Severity
9.3
AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html

First published (updated )
Severity
9.3
Buffer Overflow
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC) by restricting access to only trusted internal IP addresses.

Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

1 / 3
Source: Palo Alto Networks
First published (updated )
Severity
9.3
AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

First published (updated )
Severity
9.2
EPSS
94.86%
SQL Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

1 / 2
Source: NVD
First published (updated )
Severity
9.2
SQL Injection, XSS, OS Command Injection
AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:H/U:Amber

Multiple vulnerabilities in the Palo Alto Networks Expedition migration tool enable an attacker to read Expedition database contents and arbitrary files, as well as create and delete arbitrary files on the Expedition system. These files include information such as usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

Expedition, previously known as the Migration Tool, is a free tool that facilitates migration to the Palo Alto Networks NGFW platform from other firewall vendors and provides a temporary workspace for optimizing Palo Alto Networks security policies. Expedition is designed to only be used temporarily for migration purposes, not to be run in production. You do not need it to operate any Palo Alto Networks products or services. Expedition reached its End of Life (EoL) date on December 31, 2024. Please use the suggested alternatives listed in the Expedition End of Life Announcement (https://live.paloaltonetworks.com/t5/expedition-articles/important-update-end-of-life-announcement-for-palo-alto-networks/ta-p/589642).

These issues do not otherwise impact firewalls, Panorama appliances, Prisma Access deployments, or Cloud NGFWs.

Remedy

Ensure that all network access to Expedition is restricted to only authorized users, hosts, and networks. If you are not actively using Expedition, make sure that your Expedition software is shut down.

Remedy

The following CVEs are fixed in the specified Expedition version and all later versions* of Expedition. CVE EXPEDITION CVE-2025-0103  Expedition 1.2.100 CVE-2025-0104 Expedition 1.2.100 CVE-2025-0105 Expedition 1.2.101 CVE-2025-0106 Expedition 1.2.101 CVE-2025-0107 Expedition 1.2.100 * Expedition reached its End of Life (EoL) date (https://live.paloaltonetworks.com/t5/expedition-articles/important-update-end-of-life-announcement-for-palo-alto-networks/ta-p/589642) and is no longer supported. We added these fixes prior to the EoL date and we do not plan to make any additional updates or security fixes. Please use the suggested alternatives listed in the Expedition End of Life Announcement (https://live.paloaltonetworks.com/t5/expedition-articles/important-update-end-of-life-announcement-for-palo-alto-networks/ta-p/589642).
First published (updated )
Severity
9.2
EPSS
0.04%
SQL Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.

First published (updated )
Severity
9.2
AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

First published (updated )
Severity
9.2
Buffer Overflow
AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:Y/R:U/V:C/RE:H/U:Red

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only).

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

1 / 2
Source: MITRE
First published (updated )
Severity
9.2
Buffer Overflow
AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:Y/R:U/V:C/RE:H/U:Red

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.

First published (updated )
Severity
9.2
AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled.

The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used.

The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

1 / 2
Source: MITRE
First published (updated )
Severity
9.2
Buffer Overflow
AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Red

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.

The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. .

Panorama is not impacted by this vulnerability.

1 / 2
Source: MITRE
First published (updated )
Severity
9.2
AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html

First published (updated )
Severity
9.2
AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Palo Alto Networks incorporated the following Chromium security fixes into our products:

https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html

First published (updated )
Severity
9.2
Buffer Overflow
AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.

Panorama is impacted by this vulnerability.

1 / 2
Source: Palo Alto Networks
First published (updated )
Severity
9.1
EPSS
0.04%
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.

Remedy

This issue is fixed in PAN-OS 10.1.11, PAN-OS 10.2.5, PAN-OS 11.0.3, and all later PAN-OS versions.
First published (updated )
Severity
9.1
EPSS
0.04%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Green

An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203