Paloaltonetworks
131 known vulnerabilities
Top Products
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to
A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated admini
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enabl
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network ac
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticat
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, Global
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validatio
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3,
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) v
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endp
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged age
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a l
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenti
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an a
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffi
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated admi
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables u
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software al
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software all
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticat
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle att
Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (
Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and per
Frequently Asked Questions
How many CVEs affect Paloaltonetworks?
Paloaltonetworks has 131 CVE records in our database, including 31 critical and 62 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Paloaltonetworks vulnerabilities?
Paloaltonetworks has 31 critical severity (CVSS 9.0+) and 62 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Paloaltonetworks vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Paloaltonetworks products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Paloaltonetworks Vulnerabilities
CyberStrike scans your infrastructure for Paloaltonetworks vulnerabilities and provides real-time remediation guidance.
Get Started