CVE-2026-0257
- EPSS 0.05%
- Veröffentlicht 13.05.2026 18:15:10
- Zuletzt bearbeitet 14.05.2026 16:21:23
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not im...
CVE-2026-0262
- EPSS 0.05%
- Veröffentlicht 13.05.2026 17:49:43
- Zuletzt bearbeitet 14.05.2026 16:21:23
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NG...
CVE-2026-0263
- EPSS 0.06%
- Veröffentlicht 13.05.2026 17:47:05
- Zuletzt bearbeitet 13.05.2026 18:17:47
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) con...
CVE-2026-0228
- EPSS 0.01%
- Veröffentlicht 11.02.2026 18:16:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
CVE-2026-0227
- EPSS 0.03%
- Veröffentlicht 15.01.2026 18:45:08
- Zuletzt bearbeitet 06.02.2026 17:37:28
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.
CVE-2025-4619
- EPSS 0.1%
- Veröffentlicht 13.11.2025 20:24:19
- Zuletzt bearbeitet 15.04.2026 00:35:42
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the fire...
CVE-2025-4615
- EPSS 0.06%
- Veröffentlicht 09.10.2025 18:28:04
- Zuletzt bearbeitet 01.04.2026 01:16:39
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by...
CVE-2025-2182
- EPSS 0.02%
- Veröffentlicht 13.08.2025 17:03:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. ...
CVE-2025-4230
- EPSS 0.23%
- Veröffentlicht 12.06.2025 23:30:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to th...
CVE-2025-0136
- EPSS 0.09%
- Veröffentlicht 14.05.2025 18:12:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewa...