Palo Alto Networks Security Advisories
paloalto-psirt · A · active
https://security.paloaltonetworks.com/
Added 2026-09-29: first-party PSIRT for PAN-OS / GlobalProtect / Prisma, an edge-device line with repeated in-the-wild exploitation; until now only reached through CERT relays. RECIPE: `feed https://security.paloaltonetworks.com/rss.xml 10` (direct, newest CVE-2026-0307 GlobalProtect 2026-09-23 at probe), then `extract` the per-advisory page for the affected/fixed version table. (2026-09-29 operator-directed setup review)
Cited in 9 entries
Citation cadence
Citation days per ISO week (7 weeks of coverage span, total 7).
- CVE-2026-48907, Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)2026-06-17
- CVE-2026-48710 "BadHost", Starlette (FastAPI / vLLM / LiteLLM / MCP SDK): Pre-Auth Auth Bypass via Malformed Host Header2026-05-30
- CVE-2026-0257: PAN-OS GlobalProtect Pre-Auth VPN Authentication Bypass2026-05-30
- CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate Reuse2026-05-30
- CVE-2026-0300 PAN-OS Captive Portal, revised fix-release timelines for 10.2.13-h21 and 10.2.16-h7; wave-2 target remains 2026-05-282026-05-18
- CVE-2026-0300 PAN-OS Captive Portal, patch wave 2 delayed to 2026-05-28 for eight high-traffic build streams; mitigation remains the only option on those builds2026-05-14
- Palo Alto PAN-OS CVE-2026-0300, first-wave fixed builds now scheduled for 2026-05-13; until then interim mitigation remains the only option2026-05-12
- CVE-2026-0300, Palo Alto PAN-OS Captive Portal KEV deadline TODAY (2026-05-09); no patch exists; first patches expected 2026-05-13; CL-STA-1132 post-exploitation detail2026-05-09
- CVE-2026-0300 (PAN-OS Captive Portal unauthenticated root RCE): CISA KEV deadline is today (2026-05-09); no patch until 2026-05-132026-05-08