LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-0240

paloaltonetworks · trust protection foundation

Published
CVSS8.7
Severityhigh
WeaknessCWE-497
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-0240

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-0240.