Vulnerabilities

Palo Alto Networks Patches Dozens of Vulnerabilities 

Palo Alto Networks has fixed medium- and high-severity vulnerabilities in PAN-OS, Cortex XDR, ActiveMQ Content Pack, and Prisma Access Browser.

Palo Alto Networks

Palo Alto Networks on Wednesday informed customers about the availability of patches for dozens of vulnerabilities affecting its PAN-OS, Cortex XDR, ActiveMQ Content Pack, and Prisma Access Browser products.

Based on its severity rating of ‘high’, the most important advisory describes CVE-2024-8686, a PAN-OS command injection vulnerability that allows an authenticated attacker with admin privileges to bypass system restrictions and run arbitrary commands on the firewall as root.

The cybersecurity giant has also updated its Chromium-based Prisma Access Browser to address 29 vulnerabilities patched in recent weeks in Chromium. Many of these vulnerabilities have a ‘high severity’ rating and some are known to have been exploited in the wild

The remaining vulnerabilities have been assigned a ‘medium severity’ rating. One of them impacts PAN-OS and is related to the cleartext exposure of GlobalProtect portal passwords. 

“An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so,” the company explained.

Also in PAN-OS, Palo Alto patched a flaw that allows authenticated admins with access to the command-line interface (CLI) to read arbitrary files on the firewall. 

Advertisement. Scroll to continue reading.

Another PAN-OS security hole can enable authenticated attackers to impersonate other GlobalProtect users.

“Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker,” the company explained. 

A cleartext credentials exposure issue has been addressed in the ActiveMQ Content Pack, specifically integration with Cortex XSOAR and XSIAM.

Separately, a Cortex XDR Agent vulnerability affects Windows installations and enables an attacker with admin privileges to disable the agent. The security firm noted that this vulnerability could be leveraged by malware. 

The company says it’s not aware of in-the-wild exploitation for any of the vulnerabilities that are specific to its products. 

Palo Alto Networks has also published a bulletin to inform customers that over a dozen vulnerabilities found over the past decade in open source software do not impact its products.

Related: Palo Alto Networks Shares Remediation Advice for Hacked Firewalls

Related: Palo Alto Networks Patches Unauthenticated Command Execution Flaw in Cortex XSOAR

Related: Palo Alto Networks Addresses BlastRADIUS Vulnerability, Fixes Critical Bug in Expedition Tool

Related Content

Vulnerabilities

The flaw allows attackers to send files and execute them without authorization through an active remote session.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version