Paloaltonetworks
Paloaltonetworks Prisma Access: vulnerabilidades y CVE
Paloaltonetworks Prisma Access tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses4
Críticas0
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-0257 | Alta (7.8) | 97% | ⚠ Explotación activa | 13 may 2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.… |
| CVE-2024-3393 | Alta (8.7) | 29% | ⚠ Explotación activa | 27 dic 2024 | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-0301 | Baja (1.7) | 0.32% | — | 13 ago 2026 | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted… |
| CVE-2026-0257 | Alta (7.8) | 97% | ⚠ Explotación activa | 13 may 2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.… |
| CVE-2026-0227 | Media (6.6) | 0.75% | — | 15 ene 2026 | A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into… |
| CVE-2025-4619 | Media (6.6) | 0.56% | — | 13 nov 2025 | A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to… |
| CVE-2025-0126 | Alta (8.3) | 0.40% | — | 11 abr 2025 | When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the… |
| CVE-2024-3393 | Alta (8.7) | 29% | ⚠ Explotación activa | 27 dic 2024 | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the… |
| CVE-2024-8687 | Media (6.9) | 0.41% | — | 11 sept 2024 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or… |
| CVE-2024-3388 | Media (5) | 0.35% | — | 10 abr 2024 | A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability… |
| CVE-2022-0011 | Media (6.5) | 0.66% | — | 10 feb 2022 | PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done… |
| CVE-2021-3061 | Alta (7.2) | 0.86% | — | 10 nov 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges.… |
| CVE-2021-3060 | Alta (8.1) | 33% | — | 10 nov 2021 | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.