High severity7.8NVD Advisory· Published Jul 9, 2026· Updated Jul 16, 2026
CVE-2026-0276
CVE-2026-0276
Description
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
Affected products
2cpe:2.3:a:paloaltonetworks:cortex_xdr_broker_vm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:paloaltonetworks:cortex_xdr_broker_vm:*:*:*:*:*:*:*:*range: >=20.0.96,<31.0.58
- (no CPE)
Patches
Vulnerability mechanics
References
1- security.paloaltonetworks.com/CVE-2026-0276nvdVendor Advisory
News mentions
1- New InfraTrust report reveals infrastructure flaws admins should patch firstBleepingComputer · Jul 22, 2026