Palo Alto Networks vulnerabilities
13 CVEs tracked
Palo Alto Networks appears in the context of actively exploited threats, notably a high-severity authentication bypass in PAN-OS (CVE-2026-0257) leveraged by Qilin ransomware for initial access. Key events include a 40x surge in automated scanning against GlobalProtect portals and a coordinated credential-based campaign targeting VPN gateways. Defenders must prioritize patching for CVE-2026-0257 immediately, enhance monitoring for credential-stuffing attacks on VPN authentication infrastructure, and address multiple local privilege escalation and bypass vulnerabilities in Prisma Access products (e.g., CVE-2026-0291, CVE-2026-0295).
Azərbaycanca: Palo Alto Networks bu hesabat dövründə xüsusilə PAN-OS məhsulunda aktiv istismar olunan autentifikasiyadan yan keçmə zəifliyi (CVE-2026-0257) ilə bağlı kritik təhlükələr kontekstində görünür. Hesabatlarda Qilin ransomware qrupunun bu boşluqdan ilkin giriş üçün istifadə etməsi, həmçinin GlobalProtect portallarına qarşı koordinasiyalı avtomatlaşdırılmış skan hücumlarında 40 qat artım müşahidə olunması əsas hadisələrdir. Müdafiəçilər dərhal CVE-2026-0257 üçün təqdim olunmuş yamağı tətbiq etməli, VPN autentifikasiya infrastrukturuna qarşı kredensial əsaslı hücumlara qarşı monitorinqi gücləndirməli və Prisma Access məhsulları ilə bağlı bir neçə boşluğun (CVE-2026-0291, CVE-2026-0295) yerli imtiyaz artımına səbəb ola biləcəyini nəzərə almalıdır.
This vendor's CVEs13
- CVE-2026-0257KEVEPSS 94%
- CVE-2026-0301EPSS 0.32%
- CVE-2026-0299EPSS 0.19%
- CVE-2026-0298EPSS 0.19%
- CVE-2026-0297EPSS 0.16%
- CVE-2026-0296EPSS 0.09%
- CVE-2026-0295EPSS 0.08%
- CVE-2026-0294EPSS 0.12%
- CVE-2026-0293EPSS 0.11%
- CVE-2026-0292EPSS 0.14%
- CVE-2026-0291EPSS 0.12%
- CVE-2026-0290EPSS 0.14%
- CVE-2026-0289EPSS 0.16%
This hub is built from skopnix's own reporting on Palo Alto Networks: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.