CVE-2026-0301
- EPSS 0.31%
- Veröffentlicht 13.08.2026 02:05:25
- Zuletzt bearbeitet 18.08.2026 15:04:46
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
CVE-2026-0279
- EPSS 0.34%
- Veröffentlicht 09.07.2026 19:08:41
- Zuletzt bearbeitet 11.08.2026 13:17:49
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated use...
CVE-2026-0280
- EPSS 0.19%
- Veröffentlicht 09.07.2026 19:05:24
- Zuletzt bearbeitet 11.08.2026 13:17:49
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected ser...
CVE-2026-0281
- EPSS 0.17%
- Veröffentlicht 09.07.2026 19:03:44
- Zuletzt bearbeitet 11.08.2026 13:17:50
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a m...
CVE-2026-0282
- EPSS 0.18%
- Veröffentlicht 09.07.2026 19:02:26
- Zuletzt bearbeitet 11.08.2026 13:17:51
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimiz...
CVE-2026-0283
- EPSS 0.21%
- Veröffentlicht 09.07.2026 19:01:34
- Zuletzt bearbeitet 11.08.2026 13:17:51
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. ...
CVE-2026-0284
- EPSS 0.28%
- Veröffentlicht 09.07.2026 18:59:57
- Zuletzt bearbeitet 11.08.2026 13:17:52
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure ...
CVE-2026-0285
- EPSS 0.23%
- Veröffentlicht 09.07.2026 18:58:14
- Zuletzt bearbeitet 11.08.2026 13:17:53
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. ...
CVE-2026-0286
- EPSS 1.16%
- Veröffentlicht 09.07.2026 18:56:29
- Zuletzt bearbeitet 11.08.2026 13:17:54
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when...
CVE-2026-0287
- EPSS 0.32%
- Veröffentlicht 09.07.2026 18:51:42
- Zuletzt bearbeitet 11.08.2026 13:17:55
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplan...