CVE-2026-0256
- EPSS 0.04%
- Veröffentlicht 13.05.2026 18:18:05
- Zuletzt bearbeitet 14.05.2026 16:21:23
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series...
CVE-2026-0257
- EPSS 0.05%
- Veröffentlicht 13.05.2026 18:15:10
- Zuletzt bearbeitet 14.05.2026 16:21:23
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not im...
CVE-2026-0258
- EPSS 0.05%
- Veröffentlicht 13.05.2026 18:08:36
- Zuletzt bearbeitet 14.05.2026 16:21:23
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of se...
CVE-2026-0261
- EPSS 0.08%
- Veröffentlicht 13.05.2026 17:59:31
- Zuletzt bearbeitet 14.05.2026 16:21:23
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have acce...
CVE-2026-0262
- EPSS 0.05%
- Veröffentlicht 13.05.2026 17:49:43
- Zuletzt bearbeitet 14.05.2026 16:21:23
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NG...
CVE-2026-0263
- EPSS 0.06%
- Veröffentlicht 13.05.2026 17:47:05
- Zuletzt bearbeitet 13.05.2026 18:17:47
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) con...
CVE-2026-0264
- EPSS 0.07%
- Veröffentlicht 13.05.2026 17:40:36
- Zuletzt bearbeitet 13.05.2026 18:17:47
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGF...
CVE-2026-0265
- EPSS 0.08%
- Veröffentlicht 13.05.2026 17:38:33
- Zuletzt bearbeitet 13.05.2026 18:17:47
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS i...
CVE-2026-0300
- EPSS 14.43%
- Veröffentlicht 06.05.2026 18:57:39
- Zuletzt bearbeitet 12.05.2026 18:47:21
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series ...
CVE-2026-0228
- EPSS 0.01%
- Veröffentlicht 11.02.2026 18:16:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.