Palo Alto Networks Releases Patches for 11 New Vulnerabilities

Palo Alto Networks has issued a security bulletin on August 12, 2026, detailing 11 newly identified vulnerabilities across its product suite, including PAN-OS, GlobalProtect App, Prisma Access Agent, and Prisma Browser. These vulnerabilities encompass issues such as information disclosure, local privilege escalation, buffer overflow, certificate validation bypass, and anti-tamper bypass, with severity scores ranging from 1.1 to 7.2 on the CVSS scale.

Details of the Vulnerabilities

The most notable among these is CVE-2026-0301, a low-severity information disclosure vulnerability in PAN-OS URL Filtering, affecting Cloud NGFW and multiple PAN-OS versions, including 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access deployments on AWS and Azure. Patches are available for affected PAN-OS 11.1 and 10.2 releases, and Cloud NGFW and public-cloud Prisma Access instances have been remediated.

The GlobalProtect App has received six distinct fixes:

  • CVE-2026-0299 (CVSS 5.9): Addresses multiple local privilege escalation flaws across GlobalProtect versions 6.3, 6.2, and 6.0 on Linux, macOS, and Windows; mobile builds remain unaffected.
  • CVE-2026-0298 (CVSS 5.2): Resolves a code execution vulnerability specific to the Windows Pre-Logon Access Provider (PLAP) component.
  • CVE-2026-0297 (CVSS 5.2): Fixes a buffer overflow triggered during the UDP tunnel handshake process, impacting iOS, Android, and Chrome OS versions prior to 6.3.5.
  • CVE-2026-0296 (CVSS 4.5): Mitigates an improper certificate validation bypass affecting desktop clients.
  • CVE-2026-0295 (CVSS 4.1): Fixes a race condition leading to local privilege escalation on macOS endpoints.

Patches for several GlobalProtect App flaws on the 6.0 branch are expected by August 31, 2026, indicating ongoing remediation efforts for legacy clients.

The Prisma Access Agent is subject to four separate security disclosures:

  • CVE-2026-0294 (CVSS 6.0): A local privilege escalation vulnerability affecting Windows and macOS, with a fix expected by August 20.
  • CVE-2026-0293 (CVSS 5.6): An anti-tamper protection bypass on Windows, also with an August 20 fix ETA.
  • CVE-2026-0292 (CVSS 2.1): A local security inspection bypass on Windows, sharing the August 20 timeline.
  • CVE-2026-0291 (CVSS 1.1): An authenticated file deletion flaw on Linux, already patched in version 26.2.2.

Additionally, advisory PAN-SA-2026-0011 addresses Chromium vulnerabilities in Prisma Browser builds prior to 148.18.4.217, with a CVSS score of 7.2, the highest risk score in this update cycle.

Organizations using Prisma Browser should update to version 150.49.8.187 or later to mitigate these vulnerabilities.

Given the range of vulnerabilities and their potential impact, it’s imperative for organizations utilizing Palo Alto Networks products to promptly apply the available patches and adhere to the recommended mitigation strategies to maintain robust security postures.