Palo Alto Networks Security Advisories

1 - 25 of 460
VersionsAffectedUnaffected
7.6PAN-SA-2025-0009 Chromium: Monthly Vulnerability Update (May 2025)
Prisma Access Browser
< 135.16.8.96
>= 136.11.9.93
2025-05-142025-05-15
4.6CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.6-h1, < 11.1.7-h2, < 11.1.8
None
None
None
All
>= 11.2.5
>= 11.1.6-h1, >= 11.1.7-h2, >= 11.1.8
All
All
All
2025-05-142025-05-14
4CVE-2025-0131 GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Security SDK
MetaDefender Endpoint Security SDK 4.3.0
< 4.3.4451 on Windows
>= 4.3.4451 on Windows
2025-05-142025-05-14
2.7CVE-2025-0132 Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services
Cortex XDR Broker VM 26.0.0
< 26.0.119
>= 26.0.119
2025-05-142025-05-14
2CVE-2025-0133 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
All
< 11.2.7
< 11.1.11
< 10.2.17
All
All
None
>= 11.2.7 [ETA June 2025]
>= 11.1.11 [ETA July 2025]
>= 10.2.17 [ETA August 2025]
None
None
2025-05-142025-05-15
2.6CVE-2025-0134 Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM
Cortex XDR Broker VM 26.0.0
< 26.0.119
>= 26.0.119
2025-05-142025-05-14
1.8CVE-2025-0135 GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on Android, None on Chrome OS, None on iOS, None on Windows, None on Linux
< 6.3.3 on macOS
< 6.2.8 on macOS
All on macOS
All on macOS
None
All on Android, All on Chrome OS, All on iOS, All on Windows, All on Linux
>= 6.3.3 on macOS
>= 6.2.8 on macOS
None on macOS
None on macOS
All
2025-05-142025-05-14
1.3CVE-2025-0136 PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None
< 11.1.5
< 11.0.7
< 10.2.11
< 10.1.14-h14
None
All
All
>= 11.1.5
>= 11.0.7
>= 10.2.11
>= 10.1.14-h14
All
2025-05-142025-05-14
1.1CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
None
< 11.2.5
< 11.1.8
< 10.2.13
< 10.1.14-h14
All
>= 11.2.5
>= 11.1.8
>= 10.2.13
>= 10.1.14-h14
2025-05-142025-05-14
0.3CVE-2025-0138 Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Interface
Compute in Prisma Cloud Enterprise Edition
Prisma Cloud Compute Edition
None
< 34.00.141
All
>= 34.00.141
2025-05-142025-05-14
iPAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
PAN-OS
None
All
2025-05-142025-05-14
4CVE-2025-0120 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on macOS, None on Linux, None on iOS, None on Android, None on Chrome OS
< 6.3.3 on Windows
< 6.2.7-1077 on Windows, < 6.2.8 on Windows
All on Windows
< 6.0.12 on Windows
None
All on macOS, All on Linux, All on iOS, All on Android, All on Chrome OS
>= 6.3.3 on Windows
>= 6.2.7-1077 on Windows, >= 6.2.8 on Windows
None on Windows
>= 6.0.12 on Windows (ETA: May 2025)
All
2025-04-092025-05-02
4.3CVE-2025-0121 Cortex XDR Agent: Local Windows User Can Crash the Agent
Cortex XDR Agent 8.7
Cortex XDR Agent 8.6
Cortex XDR Agent 8.5
Cortex XDR Agent 8.3-CE
Cortex XDR Agent 7.9-CE
None on Windows
< 8.6.1 on Windows
< 8.5.2 on Windows
< 8.3.101-CE HF on Windows
< 7.9.103-CE HF on Windows
All on Windows
>= 8.6.1 on Windows
>= 8.5.2 on Windows
>= 8.3.101-CE HF on Windows
>= 7.9.103-CE HF on Windows
2025-04-092025-04-09
4.9CVE-2025-0122 Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through Burst of Crafted Packets
Prisma SD-WAN 6.5
Prisma SD-WAN 6.4
Prisma SD-WAN 6.3
Prisma SD-WAN 6.2
Prisma SD-WAN 6.1
Prisma SD-WAN 5.6
< 6.5.1
< 6.4.2
< 6.3.4
All
< 6.1.10
All
>= 6.5.1
>= 6.4.2
>= 6.3.4
None
>= 6.1.10
None
2025-04-092025-04-15
1.9CVE-2025-0123 PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.6
< 11.1.8
< 10.2.15
< 10.1.14-h13
None
All
>= 11.2.6
>= 11.1.8
>= 10.2.15 (ETA: 05/15)
>= 10.1.14-h13
All
2025-04-092025-04-09
2CVE-2025-0124 PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
All
< 11.2.1
< 11.1.5
< 11.0.6
< 10.2.10
< 10.1.14-h11
None
None (ETA end of April)
>= 11.2.1
>= 11.1.5
>= 11.0.6
>= 10.2.10
>= 10.1.14-h11
All
2025-04-092025-04-09
4.4CVE-2025-0125 PAN-OS: Improper Neutralization of Input in the Management Web Interface
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.5
< 11.0.6
< 10.2.11
< 10.1.14-h11
None
All
>= 11.2.5
>= 11.1.5
>= 11.0.6
>= 10.2.11
>= 10.1.14-h11
All
2025-04-092025-04-16
5.6CVE-2025-0126 PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.3
< 11.1.5
< 11.0.6
< 10.2.4-h25, < 10.2.9-h13, < 10.2.10-h6, < 10.2.11
< 10.1.14-h11
< 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS
All
>= 11.2.3
>= 11.1.5
>= 11.0.6
>= 10.2.4-h25, >= 10.2.9-h13, >= 10.2.10-h6, >= 10.2.11
>= 10.1.14-h11
>= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS
2025-04-092025-04-09
4CVE-2025-0127 PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
None on VM-Series
None on VM-Series
< 11.0.4 on VM-Series
< 10.2.9 on VM-Series
< 10.1.14-h13 on VM-Series
None
All
All on VM-Series
All on VM-Series
>= 11.0.4 on VM-Series
>= 10.2.9 on VM-Series
>= 10.1.14-h13 on VM-Series
All
2025-04-092025-04-09
6.6CVE-2025-0128 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None on PAN-OS
< 11.2.3
< 11.1.5
< 11.0.6
< 10.2.10-h17
< 10.1.14-h11
< 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS
All on PAN-OS
>= 11.2.3
>= 11.1.5
>= 11.0.6
>= 10.2.10-h17
>= 10.1.14-h11
>= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS
2025-04-092025-04-09
2.4CVE-2025-0119 Cortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VM
Cortex XDR Broker VM
< 26.100.3
>= 26.100.3
2025-04-092025-04-09
7.6PAN-SA-2025-0008 Chromium and Prisma Access Browser: Monthly Vulnerability Update (April 2025)
Prisma Access Browser
< 132.83.3017.1
>= 134.29.5.178
2025-04-092025-04-09
2.2CVE-2025-0118 GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on macOS, Linux, iOS, Android, Chrome OS
< 6.3.3 on Windows
< 6.2.5 on Windows
< 6.1.6 on Windows
< 6.0.11 on Windows
None
All on macOS, Linux, iOS, Android, Chrome OS
>= 6.3.3 on Windows
>= 6.2.5 on Windows
>= 6.1.6 on Windows
>= 6.0.11 on Windows
All
2025-03-122025-03-12
4.3CVE-2025-0117 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
GlobalProtect App
GlobalProtect App 6.3
GlobalProtect App 6.2
GlobalProtect App 6.1
GlobalProtect App 6.0
GlobalProtect UWP App
None on iOS, None on Android, None on Chrome OS, None on macOS
< 6.3.3 on Windows
< 6.2.6 on Windows
All on Windows
All on Windows
None
All on iOS, All on Android, All on Chrome OS, All on macOS
>= 6.3.3 on Windows*
>= 6.2.6 on Windows*
None on Windows
None on Windows (Fix version ETA: May 2025)
All
2025-03-122025-05-01
4.3CVE-2025-0116 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame
Cloud NGFW
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Prisma Access
None
< 11.2.5
< 11.1.4-h17, < 11.1.6-h6, < 11.1.8
< 10.2.10-h17, < 10.2.13-h5, < 10.2.14
< 10.1.14-h11
None
All
>= 11.2.5
>= 11.1.4-h17, >= 11.1.6-h6, >= 11.1.8
>= 10.2.10-h17, >= 10.2.13-h5, >= 10.2.14
>= 10.1.14-h11
All
2025-03-122025-04-04
1 - 25 of 460 Download
© 2025 Palo Alto Networks, Inc. All rights reserved.