Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/CyberSecurity News/Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
CyberSecurity News

Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access

Key Takeaways Palo Alto Networks has released security updates addressing 11 vulnerabilities across its product suite. Affected products include PAN-OS, GlobalProtect App, Prisma Access Agent, and...

David kimber
David kimber
August 12, 2026 4 Min Read
3 0

Key Takeaways

  • Palo Alto Networks has released security updates addressing 11 vulnerabilities across its product suite.
  • Affected products include PAN-OS, GlobalProtect App, Prisma Access Agent, and Prisma Browser.
  • Severity scores range from 1.1 to 7.2 CVSS, with no critical vulnerabilities in this release.
  • Patches are available for most issues, though some legacy GlobalProtect clients and Prisma Access Agent fixes have pending release dates.

Palo Alto Networks Issues Comprehensive Security Bulletin for August 2026

Palo Alto Networks has published its latest security bulletin dated August 12, 2026, detailing 11 new vulnerabilities. These security flaws impact a range of the company’s core offerings, including the PAN-OS operating system, the GlobalProtect App, Prisma Access Agent, and Prisma Browser. The update also incorporates a monthly rollup of Chromium fixes.

Table Of Content

  • Key Takeaways
  • Palo Alto Networks Issues Comprehensive Security Bulletin for August 2026
  • PAN-OS and Prisma Access Updates
  • Extensive Fixes for GlobalProtect App
  • Prisma Access Agent and Prisma Browser Security Updates
  • What You Should Do

The identified vulnerabilities encompass various security categories, such as information disclosure, local privilege escalation, buffer overflows, certificate validation bypasses, and anti-tamper protection bypasses. While the breadth of issues is significant, none of the newly disclosed flaws have been rated as critical severity in this update cycle, with CVSS scores ranging from a low of 1.1 to a moderate 7.2.

Cybersecurity teams are advised to thoroughly assess their environments for potential exposures, particularly those utilizing PAN-OS and associated endpoint solutions.

PAN-OS and Prisma Access Updates

One notable vulnerability, CVE-2026-0301, affects PAN-OS URL Filtering. This low-severity (CVSS 1.7) information disclosure flaw impacts Cloud NGFW and several PAN-OS branches, specifically versions 12.1, 11.2, 11.1, and 10.2. Prisma Access deployments hosted on AWS and Azure are also affected.

Palo Alto Networks has already deployed remediations for Cloud NGFW and public-cloud Prisma Access instances. Patches are also available for affected PAN-OS 11.1 and 10.2 releases. Organizations should consult the official Palo Alto Networks Security Advisories and review specific release tables to ensure all firewall management interfaces are updated.

Extensive Fixes for GlobalProtect App

The GlobalProtect App received a substantial number of fixes in this round, with six distinct CVEs disclosed:

  • CVE-2026-0299 (CVSS 5.9): This addresses multiple local privilege escalation vulnerabilities present in GlobalProtect versions 6.3, 6.2, and 6.0 across Linux, macOS, and Windows platforms. Mobile builds for iOS, Android, and Chrome OS are not affected.
  • CVE-2026-0298 (CVSS 5.2): A critical code execution vulnerability specific to the Windows Pre-Logon Access Provider (PLAP) component has been resolved.
  • CVE-2026-0297 (CVSS 5.2): A buffer overflow flaw triggered during the UDP tunnel handshake process has been patched. This impacts iOS, Android, and Chrome OS versions prior to 6.3.5.
  • CVE-2026-0296 (CVSS 4.5): An improper certificate validation bypass affecting desktop clients has been mitigated.
  • CVE-2026-0295 (CVSS 4.1): A race condition that could lead to local privilege escalation on macOS endpoints has been fixed.

It is important to note that patches for several GlobalProtect app flaws on the 6.0 branch are estimated to be available by August 31, 2026, indicating ongoing remediation efforts for older client versions.

Prisma Access Agent and Prisma Browser Security Updates

The Prisma Access Agent was subject to four separate security disclosures:

  1. CVE-2026-0294 (CVSS 6.0): A local privilege escalation vulnerability impacting both Windows and macOS, with a fix expected by August 20, 2026.
  2. CVE-2026-0293 (CVSS 5.6): An anti-tamper protection bypass on Windows, also scheduled for a fix by August 20, 2026.
  3. CVE-2026-0292 (CVSS 2.1): A local security inspection bypass on Windows, with remediation expected by August 20, 2026.
  4. CVE-2026-0291 (CVSS 1.1): An authenticated file deletion flaw on Linux, which has already been patched in version 26.2.2.

Additionally, Palo Alto Networks issued advisory PAN-SA-2026-0011 to address multiple Chromium vulnerabilities found in Prisma Browser builds earlier than 148.18.4.217. This advisory carries the highest CVSS score in this update cycle at 7.2. Organizations utilizing Prisma Browser should prioritize updating to version 150.49.8.187 or later to address these risks.

While none of the vulnerabilities disclosed in this bulletin are currently reported as being actively exploited, the volume of fixes for GlobalProtect and Prisma Access Agent highlights the ongoing importance of endpoint security posture.

What You Should Do

  • Consult the Palo Alto Networks Security Advisories for detailed information on affected versions and specific patch availability.
  • Prioritize updating internet-facing PAN-OS management interfaces and URL filtering policies.
  • Apply updates for GlobalProtect App, especially on Windows and macOS desktop clients, to mitigate privilege escalation vulnerabilities.
  • For Prisma Access Agent, plan for updates around the August 20, 2026, estimated availability date for pending fixes.
  • Immediately update Prisma Browser to version 150.49.8.187 or later to address critical Chromium vulnerabilities.
  • Ensure that all endpoint security solutions and VPN clients are running the latest available software versions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEExploitPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

China-linked Hackers Use AI Agents to Attack Taiwan Government Websites

Next Post

City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us