CVE-2026-0308
- EPSS 0.27%
- Veröffentlicht 10.09.2026 05:48:46
- Zuletzt bearbeitet 10.09.2026 14:50:07
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software o...
CVE-2026-0310
- EPSS 0.34%
- Veröffentlicht 10.09.2026 05:21:28
- Zuletzt bearbeitet 11.09.2026 04:17:13
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) conditi...
CVE-2026-0279
- EPSS 0.34%
- Veröffentlicht 09.07.2026 19:08:41
- Zuletzt bearbeitet 11.08.2026 13:17:49
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated use...
CVE-2026-0281
- EPSS 0.17%
- Veröffentlicht 09.07.2026 19:03:44
- Zuletzt bearbeitet 11.08.2026 13:17:50
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a m...
CVE-2026-0282
- EPSS 0.18%
- Veröffentlicht 09.07.2026 19:02:26
- Zuletzt bearbeitet 11.08.2026 13:17:51
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimiz...
CVE-2026-0286
- EPSS 1.16%
- Veröffentlicht 09.07.2026 18:56:29
- Zuletzt bearbeitet 11.08.2026 13:17:54
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when...
CVE-2026-0273
- EPSS 1.34%
- Veröffentlicht 10.06.2026 21:01:45
- Zuletzt bearbeitet 23.07.2026 09:10:00
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to th...
CVE-2026-0272
- EPSS 0.26%
- Veröffentlicht 10.06.2026 21:01:10
- Zuletzt bearbeitet 23.07.2026 09:10:00
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by thi...
CVE-2026-0266
- EPSS 0.13%
- Veröffentlicht 10.06.2026 20:30:04
- Zuletzt bearbeitet 23.07.2026 09:10:00
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM...
CVE-2026-0256
- EPSS 0.18%
- Veröffentlicht 13.05.2026 18:18:05
- Zuletzt bearbeitet 14.07.2026 16:39:53
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series...