Palo Alto Networks released advisories for 13 vulnerabilities in its products this week. That’s on top of more than 500 Chromium flaws it also patched for the Prisma browser.
The big one is CVE-2026-0288, a high-severity buffer overflow in PAN-OS. An unauthenticated attacker with network access to a firewall could cause a denial of service — or worse, get arbitrary code execution. All they need is specially crafted network traffic. The risk goes down if you follow best practices and restrict access to the User-ID Terminal Server Agent to trusted internal IPs.
Seven medium-severity bugs got patched too. Five of those are in PAN-OS: DoS, OS command execution as root, SSRF, info disclosure, and authentication bypass. The nastier ones require admin-level access first. The other two medium-rated flaws hit Prisma Access Agent — they open the door for MitM attacks, VPN traffic interception, and DLP policy bypass.
Five low-severity issues round out the batch: privilege escalation, XSS-based code execution, firewall policy bypass, file deletion, and information disclosure.
Palo Alto says it hasn’t seen any of these exploited in the wild yet. But attackers have been known to target the company’s products, so patching sooner than later makes sense.
The company credits both external researchers and its own AI-driven internal discovery for finding these bugs. They’ve been finding more vulnerabilities since putting AI to work on their own code.
