VYPR
patchPublished Aug 12, 2026· 1 source

Palo Alto Networks Patches 11 Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access

Palo Alto Networks has released security updates for 11 vulnerabilities affecting its PAN-OS, GlobalProtect, and Prisma Access products, with CVSS scores ranging from 1.1 to 7.2.

Palo Alto Networks has issued a significant security bulletin detailing eleven new vulnerabilities discovered across its product suite, including PAN-OS, the GlobalProtect App, Prisma Access Agent, and Prisma Browser. The disclosed flaws encompass a range of security weaknesses such as information disclosure, local privilege escalation, buffer overflow, certificate validation bypass, and anti-tamper bypass. While none of the vulnerabilities reached critical severity, with CVSS scores ranging from a low 1.1 to a moderate 7.2, the breadth of affected products necessitates attention from security teams managing Palo Alto Networks infrastructure.

The most notable vulnerability affecting core infrastructure is CVE-2026-0301, a low-severity (CVSS 1.7) information disclosure flaw within PAN-OS URL Filtering. This vulnerability impacts Cloud NGFW and multiple PAN-OS release branches, including 11.1, 11.2, 12.1, and 10.2, as well as Prisma Access deployments hosted on AWS and Azure. Palo Alto Networks has already remediated affected cloud instances and provided fixes for the on-premises PAN-OS releases, urging organizations to consult specific release tables for their firewall management interfaces.

The GlobalProtect App is the most heavily impacted product in this patch cycle, with six distinct vulnerabilities addressed. These include multiple local privilege escalation flaws (CVE-2026-0299) affecting desktop versions on Linux, macOS, and Windows across branches 6.3, 6.2, and 6.0. Other fixes for GlobalProtect address code execution in the Windows Pre-Logon Access Provider (CVE-2026-0298), a buffer overflow during UDP tunnel handshakes on mobile clients (CVE-2026-0297), improper certificate validation bypass on desktop clients (CVE-2026-0296), and a race condition leading to local privilege escalation on macOS (CVE-2026-0295). Notably, patches for some GlobalProtect app flaws on the 6.0 branch are expected by August 31, 2026, indicating ongoing remediation for older versions.

Prisma Access Agent also sees several security updates, with four separate vulnerabilities disclosed. CVE-2026-0294 (CVSS 6.0) addresses a local privilege escalation flaw on Windows and macOS, with a fix expected by August 20, 2026. A similar privilege escalation vulnerability (CVE-2026-0292) with a lower CVSS score of 2.1 also affects Windows, with the same expected patch date. Additionally, an anti-tamper protection bypass on Windows (CVE-2026-0293) and an authenticated file deletion flaw on Linux (CVE-2026-0291) are addressed, with the latter already patched.

Beyond the specific product agents, Palo Alto Networks also issued advisory PAN-SA-2026-0011, which tackles a batch of Chromium vulnerabilities within the Prisma Browser. This rollup includes a flaw with the highest CVSS score of the release cycle, 7.2, impacting builds prior to version 148.18.4.217. Users of Prisma Browser are strongly advised to update to version 150.49.8.187 or later to mitigate these risks.

While Palo Alto Networks has not indicated that any of these vulnerabilities are currently being actively exploited in the wild, the sheer volume of fixes, particularly for GlobalProtect and Prisma Access Agents, highlights the persistent threat landscape targeting endpoint security. Security administrators are urged to prioritize patching internet-facing PAN-OS management interfaces and URL filtering policies, followed by GlobalProtect clients on Windows and macOS, especially given the privilege escalation vectors.

This coordinated disclosure and patching effort by Palo Alto Networks underscores the ongoing need for diligent vulnerability management. The company's proactive approach in identifying and addressing these flaws, even those with lower severity, contributes to the overall security posture of organizations relying on its comprehensive security solutions. Staying informed about these regular updates is crucial for maintaining robust defenses against evolving cyber threats.

Synthesized by Vypr AI