CVE-2026-0288
- EPSS 0.96%
- Veröffentlicht 08.07.2026 20:14:32
- Zuletzt bearbeitet 11.08.2026 13:17:56
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially exec...
CVE-2026-0273
- EPSS 1.34%
- Veröffentlicht 10.06.2026 21:01:45
- Zuletzt bearbeitet 23.07.2026 09:10:00
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to th...
CVE-2026-0272
- EPSS 0.26%
- Veröffentlicht 10.06.2026 21:01:10
- Zuletzt bearbeitet 23.07.2026 09:10:00
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by thi...
CVE-2026-0269
- EPSS 0.22%
- Veröffentlicht 10.06.2026 20:54:29
- Zuletzt bearbeitet 23.07.2026 09:10:00
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the...
CVE-2026-0266
- EPSS 0.13%
- Veröffentlicht 10.06.2026 20:30:04
- Zuletzt bearbeitet 23.07.2026 09:10:00
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM...
CVE-2026-0256
- EPSS 0.18%
- Veröffentlicht 13.05.2026 18:18:05
- Zuletzt bearbeitet 14.07.2026 16:39:53
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series...
CVE-2026-0257
- EPSS 93.91%
- Veröffentlicht 13.05.2026 18:15:10
- Zuletzt bearbeitet 09.06.2026 12:47:03
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not im...
CVE-2026-0258
- EPSS 0.33%
- Veröffentlicht 13.05.2026 18:08:36
- Zuletzt bearbeitet 14.07.2026 15:52:15
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of se...
CVE-2026-0259
- EPSS 0.34%
- Veröffentlicht 13.05.2026 18:05:45
- Zuletzt bearbeitet 14.07.2026 15:52:52
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running i...
CVE-2026-0261
- EPSS 1.4%
- Veröffentlicht 13.05.2026 17:59:31
- Zuletzt bearbeitet 14.07.2026 16:39:45
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have acce...