CVE-2026-0256
- EPSS 0.18%
- Veröffentlicht 13.05.2026 18:18:05
- Zuletzt bearbeitet 14.07.2026 16:39:53
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series...
CVE-2026-0257
- EPSS 93.91%
- Veröffentlicht 13.05.2026 18:15:10
- Zuletzt bearbeitet 09.06.2026 12:47:03
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not im...
CVE-2026-0258
- EPSS 0.33%
- Veröffentlicht 13.05.2026 18:08:36
- Zuletzt bearbeitet 14.07.2026 15:52:15
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of se...
CVE-2026-0261
- EPSS 1.4%
- Veröffentlicht 13.05.2026 17:59:31
- Zuletzt bearbeitet 14.07.2026 16:39:45
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have acce...
CVE-2026-0262
- EPSS 0.36%
- Veröffentlicht 13.05.2026 17:49:43
- Zuletzt bearbeitet 14.07.2026 16:39:38
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NG...
CVE-2026-0264
- EPSS 0.47%
- Veröffentlicht 13.05.2026 17:40:36
- Zuletzt bearbeitet 14.07.2026 15:49:35
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGF...
CVE-2026-0265
- EPSS 0.38%
- Veröffentlicht 13.05.2026 17:38:33
- Zuletzt bearbeitet 14.07.2026 15:50:50
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS i...
CVE-2026-0300
- EPSS 32.07%
- Veröffentlicht 06.05.2026 18:57:39
- Zuletzt bearbeitet 12.05.2026 18:47:21
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series ...
CVE-2026-24858
- EPSS 85.84%
- Veröffentlicht 27.01.2026 19:18:23
- Zuletzt bearbeitet 09.06.2026 18:30:13
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15...
CVE-2025-59718
- EPSS 63.44%
- Veröffentlicht 09.12.2025 17:20:11
- Zuletzt bearbeitet 09.06.2026 12:47:10
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 throug...