Palo Alto Products Multiple Vulnerabilities
Release Date: 10 Sep 2026
Multiple vulnerabilities were identified in Palo Alto Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution and cross-site scripting on the targeted system.
Impact
- Remote Code Execution
- Denial of Service
- Cross-Site Scripting
- Elevation of Privilege
System / Technologies affected
- Cloud NGFW all versions on AWS and Azure
- GlobalProtect App 6.0 versions earlier than 6.0.15 on macOS, Linux and Windows
- GlobalProtect App 6.2 versions earlier than 6.2.8-h14 on macOS and Windows
- GlobalProtect App 6.3 versions earlier than 6.3.3-h15 on macOS, Linux and Windows
- GlobalProtect App all versions on iOS, Android, ChromeOS
- PAN-OS 10.2 versions earlier than 10.2.7-h37
- PAN-OS 10.2 versions earlier than 10.2.10-h40
- PAN-OS 10.2 versions earlier than 10.2.13-h24
- PAN-OS 10.2 versions earlier than 10.2.16-h10
- PAN-OS 10.2 versions earlier than 10.2.18-h10
- PAN-OS 11.1 versions earlier than 11.1.4-h36
- PAN-OS 11.1 versions earlier than 11.1.6-h38
- PAN-OS 11.1 versions earlier than 11.1.7-h10
- PAN-OS 11.1 versions earlier than 11.1.10-h33
- PAN-OS 11.1 versions earlier than 11.1.13-h12
- PAN-OS 11.1 versions earlier than 11.1.16-h2
- PAN-OS 11.2 versions earlier than 11.2.4-h21
- PAN-OS 11.2 versions earlier than 11.2.7-h20
- PAN-OS 11.2 versions earlier than 11.2.10-h14
- PAN-OS 11.2 versions earlier than 11.2.13-h2
- PAN-OS 12.1 versions earlier than 12.1.4-h10
- PAN-OS 12.1 versions earlier than 12.1.7-h5
- PAN-OS 12.1 versions earlier than 12.1.10
- PAN-OS 12.2 versions earlier than 12.2.3
- Prisma Access 10.2 versions earlier than 10.2.10-h40
- Prisma Access 11.2 versions earlier than 11.2.7-h20
- Prisma Access 12.1 versions earlier than 12.1.7-h5
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://security.paloaltonetworks.com/
- https://security.paloaltonetworks.com/CVE-2026-0307
- https://security.paloaltonetworks.com/CVE-2026-0308
- https://security.paloaltonetworks.com/CVE-2026-0309
- https://security.paloaltonetworks.com/CVE-2026-0310
沒有留言:
發佈留言