Search Results (405 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-0277 3 Apple, Palo Alto Networks, Paloaltonetworks 3 Iphone Os, Prisma Access Agent, Prisma Access Agent 2026-07-10 5.9 Medium
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
CVE-2026-0278 3 Microsoft, Palo Alto Networks, Paloaltonetworks 3 Windows, Prisma Access Agent, Prisma Access Agent 2026-07-10 7.8 High
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
CVE-2026-45170 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks 3 Pam Sh Connector, Vendor Pam, Idira Privilege Cloud Connector 2026-06-23 8.8 High
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
CVE-2026-45178 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks 4 Conjur Enterprise, Conjur Enterprise, Idira Secrets Manager and 1 more 2026-06-12 8.1 High
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
CVE-2026-45177 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks 3 Conjur Cloud, Conjur Cloud Edge Finding Only , Idira Secrets Manager Edge 2026-06-12 9.1 Critical
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20
CVE-2026-45176 6 Apple, Cyberark, Cyberark Software A Palo Alto Networks Company and 3 more 6 Macos, Endpoint Privilege Manager, Idira Endpoint Privilege Manager and 3 more 2026-06-12 7.8 High
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19
CVE-2026-45175 6 Apple, Cyberark, Cyberark Software A Palo Alto Networks Company and 3 more 6 Macos, Endpoint Privilege Manager, Idira Endpoint Privilege Manager and 3 more 2026-06-12 7.8 High
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19
CVE-2026-45174 4 Cyberark, Cyberark Software A Palo Alto Networks Company, Linux and 1 more 4 Endpoint Privileged Manager, Idira Endpoint Privilege Manager, Linux Kernel and 1 more 2026-06-12 7.8 High
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19
CVE-2026-45173 6 Cyberark, Cyberark Software A Palo Alto Networks Company, Google and 3 more 6 Identity Browser Extensions, Identity Browser Extensions, Chrome and 3 more 2026-06-12 6.5 Medium
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
CVE-2026-45172 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks 3 Privileged Session Manager, Pam Self-hosted Privilege Cloud, Idira Privileged Session Manager For Ssh 2026-06-12 8.8 High
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18
CVE-2026-45171 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks 3 Privileged Session Manager, Privileged Session Manager Vault, Idira Privileged Session Manager 2026-06-12 8.8 High
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
CVE-2026-45169 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks 3 Pam Sh Vault, Pam Sh Vault, Idira Privileged Access Manager Vault 2026-06-12 8.6 High
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
CVE-2026-0266 2 Palo Alto Networks, Paloaltonetworks 4 Cloud Ngfw, Pan-os, Prisma Access and 1 more 2026-06-11 4.8 Medium
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.
CVE-2026-0267 2 Palo Alto Networks, Paloaltonetworks 3 Globalprotect App, Globalprotect Uwp App, Globalprotect 2026-06-11 5.5 Medium
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
CVE-2026-0268 3 Linux, Palo Alto Networks, Paloaltonetworks 3 Linux Kernel, Prisma Access Agent, Prisma Access Agent 2026-06-11 4.4 Medium
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
CVE-2026-0269 2 Palo Alto Networks, Paloaltonetworks 5 Cloud Ngfw, Pan-os, Panorama and 2 more 2026-06-11 5.7 Medium
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
CVE-2026-0270 3 Linux, Palo Alto Networks, Paloaltonetworks 3 Linux Kernel, Cortex Xsoar, Cortex Xsoar 2026-06-11 7.5 High
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
CVE-2026-0271 3 Linux, Palo Alto Networks, Paloaltonetworks 3 Linux Kernel, Prisma Access Agent, Prisma Access Agent 2026-06-11 7.8 High
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
CVE-2026-0274 2 Palo Alto Networks, Paloaltonetworks 4 Cortex Xsiam Commvaultsecurityiq Marketplace, Cortex Xsoar Commvaultsecurityiq Marketplace, Cortex Xsiam Commvaultsecurityiq Marketplace and 1 more 2026-06-11 9.1 Critical
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
CVE-2026-0272 2 Palo Alto Networks, Paloaltonetworks 4 Cloud Ngfw, Pan-os, Prisma Access and 1 more 2026-06-11 7.2 High
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.