Palo Alto Networks / Pan-OS
235 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-0308 | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface | LOW | 1.1 | Sep 10, 2026 |
| CVE-2026-0309 | PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration | MEDIUM | 4.0 | Sep 10, 2026 |
| CVE-2026-0310 | PAN-OS: Buffer Overflow Vulnerability via XML Processing | HIGH | 7.2 | Sep 10, 2026 |
| CVE-2026-0301 | PAN-OS: Information Disclosure Vulnerability in URL Filtering | LOW | 1.7 | Aug 13, 2026 |
| CVE-2026-0279 | PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities | LOW | 1.3 | Jul 9, 2026 |
| CVE-2026-0280 | PAN-OS: IPv6 Firewall Policy Bypass | LOW | 1.7 | Jul 9, 2026 |
| CVE-2026-0281 | PAN-OS: Information Disclosure Vulnerability in Management Web Interface | LOW | 2.1 | Jul 9, 2026 |
| CVE-2026-0282 | PAN-OS: File Deletion Vulnerability in Management Web Interface | LOW | 2.7 | Jul 9, 2026 |
| CVE-2026-0283 | PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) | MEDIUM | 4.5 | Jul 9, 2026 |
| CVE-2026-0284 | PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) | MEDIUM | 4.7 | Jul 9, 2026 |
| CVE-2026-0285 | PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface | MEDIUM | 4.7 | Jul 9, 2026 |
| CVE-2026-0286 | PAN-OS: Authenticated Command Injection in CLI | MEDIUM | 6.0 | Jul 9, 2026 |
| CVE-2026-0287 | PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing | MEDIUM | 6.6 | Jul 9, 2026 |
| CVE-2026-0288 | PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent | HIGH | 7.2 | Jul 8, 2026 |
| CVE-2026-0273 | PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI | MEDIUM | 6.1 | Jun 10, 2026 |
| CVE-2026-0272 | PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) | MEDIUM | 6.0 | Jun 10, 2026 |
| CVE-2026-0269 | PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing | MEDIUM | 4.6 | Jun 10, 2026 |
| CVE-2026-0266 | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface | LOW | 1.1 | Jun 10, 2026 |
| CVE-2026-0256 | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface | MEDIUM | 4.4 | May 13, 2026 |
| CVE-2026-0257 KEV | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities | HIGH | 7.8 | May 13, 2026 |
| CVE-2026-0258 | PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching | MEDIUM | 4.8 | May 13, 2026 |
| CVE-2026-0259 | WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B) | MEDIUM | 5.0 | May 13, 2026 |
| CVE-2026-0261 | PAN-OS: Authenticated Admin Command Injection Vulnerability | MEDIUM | 6.1 | May 13, 2026 |
| CVE-2026-0262 | PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing | MEDIUM | 6.6 | May 13, 2026 |
| CVE-2026-0263 | PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing | HIGH | 7.2 | May 13, 2026 |
Showing 1 to 25 of 235 CVEs