Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-0245 — Prisma Access Agent: Information Disclosure Vulnerabilities

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Andro…

prisma_access_agent | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.2 MEDIUM
CVE-2026-0244 — Prisma SD-WAN: Improper Certificate Validation Vulnerability

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

| Misconfiguration
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.1 MEDIUM
CVE-2026-0242 — Trust Protection Foundation: SQL Injection Vulnerability

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an at…

May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.1 MEDIUM
CVE-2026-0241 — Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

trust_protection_foundation | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.5 MEDIUM
CVE-2026-0240 — Trust Protection Foundation: Sensitive Information Disclosure Vulnerability

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue…

trust_protection_foundation | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.9 MEDIUM
CVE-2026-0239 — Chronosphere Chronocollector Information Disclosure Vulnerability

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

chronosphere_chronocollector | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
1.1 LOW
CVE-2026-0238 — Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

broker_vm | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.3 HIGH
CVE-2026-0236 — Prisma Browser: Code Injection Enables Security Controls Bypass

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverag…

prisma_browser | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.8 MEDIUM
CVE-2026-0235 — Prisma Browser: Access and Data Rule Bypass

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

prisma_browser | Race Condition
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
Showing 20 of 6989 Results