2026年9月10日星期四

Palo Alto Products Multiple Vulnerabilities

Palo Alto Products Multiple Vulnerabilities

Release Date: 10 Sep 2026

Multiple vulnerabilities were identified in Palo Alto Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution and cross-site scripting on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Cross-Site Scripting
  • Elevation of Privilege

System / Technologies affected

  • Cloud NGFW all versions on AWS and Azure
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on macOS, Linux and Windows
  • GlobalProtect App 6.2 versions earlier than 6.2.8-h14 on macOS and Windows
  • GlobalProtect App 6.3 versions earlier than 6.3.3-h15 on macOS, Linux and Windows
  • GlobalProtect App all versions on iOS, Android, ChromeOS
  • PAN-OS 10.2 versions earlier than 10.2.7-h37
  • PAN-OS 10.2 versions earlier than 10.2.10-h40
  • PAN-OS 10.2 versions earlier than 10.2.13-h24
  • PAN-OS 10.2 versions earlier than 10.2.16-h10
  • PAN-OS 10.2 versions earlier than 10.2.18-h10
  • PAN-OS 11.1 versions earlier than 11.1.4-h36
  • PAN-OS 11.1 versions earlier than 11.1.6-h38
  • PAN-OS 11.1 versions earlier than 11.1.7-h10
  • PAN-OS 11.1 versions earlier than 11.1.10-h33
  • PAN-OS 11.1 versions earlier than 11.1.13-h12
  • PAN-OS 11.1 versions earlier than 11.1.16-h2
  • PAN-OS 11.2 versions earlier than 11.2.4-h21
  • PAN-OS 11.2 versions earlier than 11.2.7-h20
  • PAN-OS 11.2 versions earlier than 11.2.10-h14
  • PAN-OS 11.2 versions earlier than 11.2.13-h2
  • PAN-OS 12.1 versions earlier than 12.1.4-h10
  • PAN-OS 12.1 versions earlier than 12.1.7-h5
  • PAN-OS 12.1 versions earlier than 12.1.10
  • PAN-OS 12.2 versions earlier than 12.2.3
  • Prisma Access 10.2 versions earlier than 10.2.10-h40
  • Prisma Access 11.2 versions earlier than 11.2.7-h20
  • Prisma Access 12.1 versions earlier than 12.1.7-h5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

MongoDB 多個漏洞

MongoDB 多個漏洞 發佈日期: 2026年09月10日 於 MongoDB 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。 影響 阻斷服務 資料洩露 遠端執行程式碼 繞過保安限制...