| CVE-2026-0284 | 9.9 | critical | pan-os | An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software | 58d ago |
| CVE-2026-0263 | 9.8 | critical | pan-os | A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenti | 115d ago |
| CVE-2026-0264 | 9.8 | critical | pan-os | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software all | 115d ago |
| CVE-2026-0258 | 9.1 | critical | pan-os | A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® softwa | 115d ago |
| CVE-2026-0274 | 9.1 | critical | cortex xsiam commvaultsecurityiq marketplace | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cor | 87d ago |
| CVE-2026-45177 | 9.1 | critical | idira secrets manager edge | Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authenti | 86d ago |
| CVE-2026-0257exploited | 9.1 | critical | pan-os | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® softwar | 115d ago |
| CVE-2026-0259 | 8.8 | high | pan-os | An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enab | 115d ago |
| CVE-2026-45170 | 8.8 | high | idira privilege cloud connector | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration sce | 86d ago |
| CVE-2026-45172 | 8.8 | high | idira privileged session manager for ssh | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14 | 86d ago |
| CVE-2026-45171 | 8.8 | high | idira privileged session manager | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager ( | 86d ago |
| CVE-2026-0240 | 8.7 | high | trust protection foundation | An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain | 115d ago |
| CVE-2026-45169 | 8.6 | high | idira privileged access manager vault | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhib | 85d ago |
| CVE-2026-0250 | 8.1 | high | globalprotect | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middl | 115d ago |
| CVE-2026-0265 | 8.1 | high | pan-os | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker w | 115d ago |
| CVE-2026-0244 | 8.1 | high | prisma sd-wan | An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-mid | 115d ago |
| CVE-2026-45178 | 8.1 | high | idira secrets manager | Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluste | 86d ago |
| CVE-2026-0246 | 7.8 | high | prisma access agent | A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a loca | 115d ago |
| CVE-2026-0276 | 7.8 | high | cortex xdr broker vm | A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated us | 58d ago |
| CVE-2026-0299 | 7.8 | high | globalprotect | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to esca | 24d ago |
| CVE-2026-0236 | 7.8 | high | prisma browser | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to | 115d ago |
| CVE-2026-0278 | 7.8 | high | prisma access agent | Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows | 58d ago |
| CVE-2026-45176 | 7.8 | high | idira endpoint privilege manager | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileg | 86d ago |
| CVE-2026-0251 | 7.8 | high | globalprotect | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user | 115d ago |
| CVE-2026-0271 | 7.8 | high | prisma access agent | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enable | 87d ago |
| CVE-2026-45175 | 7.8 | high | idira endpoint privilege manager | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agen | 86d ago |
| CVE-2026-0237 | 7.8 | high | prisma browser | An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to prop | 115d ago |
| CVE-2026-0247 | 7.8 | high | prisma access agent | Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local a | 115d ago |
| CVE-2026-45174 | 7.8 | high | idira endpoint privilege manager | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromi | 86d ago |
| CVE-2026-0262 | 7.5 | high | pan-os | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker | 115d ago |
| CVE-2026-0301 | 7.5 | high | cloud ngfw | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables | 24d ago |
| CVE-2026-0288 | 7.5 | high | pan-os | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks | 59d ago |
| CVE-2026-0287 | 7.5 | high | cloud ngfw | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker | 58d ago |
| CVE-2026-0270 | 7.5 | high | cortex xsoar | A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauth | 87d ago |
| CVE-2026-0261 | 7.2 | high | pan-os | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administr | 115d ago |
| CVE-2026-0280 | 7.2 | high | pan-os | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthen | 58d ago |
| CVE-2026-0283 | 7.2 | high | pan-os | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS softw | 58d ago |
| CVE-2026-0273 | 7.2 | high | pan-os | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to | 87d ago |
| CVE-2026-0286 | 7.2 | high | pan-os | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authent | 58d ago |
| CVE-2026-0272 | 7.2 | high | pan-os | A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator w | 87d ago |
| CVE-2026-0241 | 7.2 | high | trust protection foundation | Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls an | 115d ago |
| CVE-2026-0281 | 7.1 | high | pan-os | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker | 58d ago |