VYPR

VM Series

by Paloaltonetworks

CVEs (4)

  • CVE-2026-0300CriKEVMay 6, 2026
    risk 0.78cvss 9.8epss 0.32

    A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending…

  • CVE-2026-0286HigJul 9, 2026
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to…

  • CVE-2026-0261HigMay 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web…

  • CVE-2020-1978MedApr 8, 2020
    risk 0.38cvss 5.8epss 0.00

    TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials associated with the…