

Affected Environment
PAN-OS, GlobalProtect App, Prisma Access, Prisma Access Agent, Prisma Browser, and Cortex XDR Broker VM deployments.
Threat Overview
Multiple vulnerabilities enable buffer overflow, command injection, XSS, privilege escalation, and endpoint DLP bypass across products.
Exposure Timeline
Published 10 September 2026; highest CVSS is 7.7 via Chromium updates, with no critical rated flaws.
Attack Surface
Management and dataplane interfaces, GlobalProtect app across platforms, and Prisma Access Agent DLP enforcement.
Technical Root Cause
XML processing buffer overflow, Luna HSM CLI command injection, stored XSS, and local privilege escalation weaknesses.
Exploitation Pathway
Unauthenticated network attacker triggers buffer overflow, or local user escalates privileges or bypasses DLP controls.
Operational Impact
Successful exploitation may cause denial of service, root code execution, or bypassed DLP data exfiltration controls.
Strategic Impact
Perimeter firewall and endpoint agent compromise weakens network segmentation and data loss prevention posture.
Required Mitigation
Upgrade PAN-OS, GlobalProtect App, Prisma Access Agent, and Prisma Browser to fixed versions listed.
Incident Response Guidance
Restrict management interface access to trusted IPs, monitor for privilege escalation, and verify agent versions.
References
Palo Alto Networks Security Advisories.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




