Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-0259 — WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Ap…

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerabili…

wildfire_wf-500_and_wf-500-b | Remote | Path Traversal
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.8 MEDIUM
CVE-2026-0258 — PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests…

pan-os prisma_access | Remote | Server-Side Request Forgery
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-0257 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability - [Actively Exploited]

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized …

pan-os prisma_access prisma_access pan-os | CISA KEV Remote | Authentication
May 13, 2026 Jun 01, 2026
May 13, 2026
Jun 01, 2026
4.4 MEDIUM
CVE-2026-0256 — PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This …

pan-os | Remote | Cross-Site Scripting
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.9 MEDIUM
CVE-2026-0251 — GlobalProtect App: Local Privilege Escalation Vulnerabilities

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS an…

globalprotect_app | Authentication
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.2 MEDIUM
CVE-2026-0250 — GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with S…

May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.9 MEDIUM
CVE-2026-0249 — GlobalProtect App: Certificate Validation Bypass Vulnerabilities

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint…

globalprotect_app | Cryptography
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.2 MEDIUM
CVE-2026-0248 — Prisma Access Agent: Improper Certificate Validation Vulnerability

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By pr…

prisma_access_agent | Cryptography
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.9 MEDIUM
CVE-2026-0247 — Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.

prisma_access_agent | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.9 MEDIUM
CVE-2026-0246 — Prisma Access Agent: Local Privilege Escalation Vulnerability

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on ma…

prisma_access_agent | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-0245 — Prisma Access Agent: Information Disclosure Vulnerabilities

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Andro…

prisma_access_agent | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.2 MEDIUM
CVE-2026-0244 — Prisma SD-WAN: Improper Certificate Validation Vulnerability

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

| Misconfiguration
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.1 MEDIUM
CVE-2026-0242 — Trust Protection Foundation: SQL Injection Vulnerability

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an at…

May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.1 MEDIUM
CVE-2026-0241 — Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

trust_protection_foundation | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.5 MEDIUM
CVE-2026-0240 — Trust Protection Foundation: Sensitive Information Disclosure Vulnerability

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue…

trust_protection_foundation | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
4.9 MEDIUM
CVE-2026-0239 — Chronosphere Chronocollector Information Disclosure Vulnerability

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

chronosphere_chronocollector | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
1.1 LOW
CVE-2026-0238 — Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

broker_vm | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.3 HIGH
CVE-2026-0236 — Prisma Browser: Code Injection Enables Security Controls Bypass

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverag…

prisma_browser | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.8 MEDIUM
CVE-2026-0235 — Prisma Browser: Access and Data Rule Bypass

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

prisma_browser | Race Condition
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
9.8 CRITICAL
CVE-2026-45411 — vm2: Sandbox Breakout Using Async Generator

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the r…

vm2 | Remote | Memory Corruption
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
Showing 20 of 7162 Results