VORANT. Threat Intelligence Sign in Get the full feed

Palo Alto Networks patches multiple PAN-OS flaws

elevated vulnerability technologytelecommunications

CERT-FR advisory details multiple vulnerabilities in Palo Alto Networks PAN-OS, GlobalProtect, Prisma and Cortex products enabling RCE, DoS, XSS and privilege escalation.

CERT-FR has published an advisory (CERTFR-2026-AVI-1156) summarizing a batch of vulnerabilities disclosed by Palo Alto Networks on 09 September 2026 across a wide range of products, including PAN-OS (multiple hotfix branches from 10.2 through 12.2), GlobalProtect App (Android, ChromeOS, iOS and Windows/Linux clients), Prisma Access, Prisma Access Agent, Prisma Browser, Cloud NGFW, Cortex XDR Broker, and Checkov by Prisma Cloud. The vulnerabilities collectively allow an attacker to achieve remote arbitrary code execution, remote denial of service, indirect remote code injection (XSS), and privilege escalation; some issues are unspecified by the vendor pending further detail. No public exploitation has been confirmed in this advisory.

The advisory references numerous CVE identifiers (CVE-2026-0302 through CVE-2026-0310, plus a further set of CVE-2026-76xxx, 79xxx and 84xxx entries) tied to individual Palo Alto Networks security bulletins and a PAN-SA advisory. Given the breadth of affected products — spanning core firewall OS, VPN/endpoint agents, cloud access, and Cortex components — organizations running Palo Alto Networks infrastructure should treat this as a priority patch cycle, particularly for internet-facing PAN-OS and GlobalProtect deployments where RCE and DoS vectors carry the highest operational risk.

Defenders should identify all affected product versions in their estate (PAN-OS hotfix branches, GlobalProtect client versions, Prisma Access/Agent/Browser versions, Cortex XDR Broker, Cloud NGFW, and Checkov) and apply the vendor-supplied patches referenced in the official Palo Alto Networks security bulletins. Until patched, apply standard hardening (restrict management interface exposure, monitor for anomalous traffic/crashes on PAN-OS and GlobalProtect services) as compensating controls.

Mentioned in this report

Vulnerabilities CVE-2026-0302CVE-2026-0303CVE-2026-0304CVE-2026-0305CVE-2026-0306CVE-2026-0307CVE-2026-0308CVE-2026-0309CVE-2026-0310CVE-2026-76020CVE-2026-76022CVE-2026-76038CVE-2026-76046CVE-2026-76047CVE-2026-79016CVE-2026-79032CVE-2026-79118CVE-2026-79195CVE-2026-79282CVE-2026-79286CVE-2026-79290CVE-2026-79293CVE-2026-84348CVE-2026-84350CVE-2026-84351CVE-2026-84357CVE-2026-84358CVE-2026-84359

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1156

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free