CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access

Cybersecurity News Archived Aug 12, 2026 ✓ Full text saved

Palo Alto Networks has released its August 12, 2026 security bulletin, disclosing 11 new vulnerabilities affecting PAN-OS, the GlobalProtect App, Prisma Access Agent, and Prisma Browser, along with a monthly Chromium update rollup. The patch batch spans information disclosure, local privilege escalation, buffer overflow, certificate validation bypass, and anti-tamper bypass flaws. Severity scores range from […] The post Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProte

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access By Guru Baran August 12, 2026 Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access Palo Alto Networks has released its August 12, 2026 security bulletin, disclosing 11 new vulnerabilities affecting PAN-OS, the GlobalProtect App, Prisma Access Agent, and Prisma Browser, along with a monthly Chromium update rollup. The patch batch spans information disclosure, local privilege escalation, buffer overflow, certificate validation bypass, and anti-tamper bypass flaws. Severity scores range from a low 1.1 to a moderate 7.2 on the CVSS scale, meaning none of the newly published issues reach critical severity in this release cycle. Security teams monitoring PAN-OS vulnerabilities should evaluate endpoint exposures across enterprise environments. Palo Alto Networks Patches 11 New Vulnerabilities The most notable infrastructure entry, CVE-2026-0301, is a low-severity (CVSS 1.7) information disclosure vulnerability in PAN-OS URL Filtering. It impacts Cloud NGFW and multiple PAN-OS release branches, including 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access deployments hosted on AWS and Azure. Fixes are available across the affected PAN-OS 11.1 and 10.2 releases, and Cloud NGFW and public-cloud Prisma Access instances have already been remediated by Palo Alto Networks. As detailed in the official Palo Alto Networks Security Advisories, organizations should review specific release tables to ensure all firewall management interfaces are updated. Following broader Palo Alto security news helps enterprise administrators stay informed about system updates. The GlobalProtect App received the highest concentration of fixes this month, with six distinct CVEs disclosed: CVE-2026-0299 (CVSS 5.9): Addresses multiple local privilege escalation flaws across GlobalProtect 6.3, 6.2, and 6.0 on Linux, macOS, and Windows; mobile builds (iOS, Android, Chrome OS) remain unaffected. CVE-2026-0298 (CVSS 5.2): Resolves a code execution vulnerability specific to the Windows Pre-Logon Access Provider (PLAP) component. CVE-2026-0297 (CVSS 5.2): Fixes a buffer overflow triggered during the UDP tunnel handshake process, impacting iOS, Android, and Chrome OS versions prior to 6.3.5. CVE-2026-0296 (CVSS 4.5): Mitigates an improper certificate validation bypass affecting desktop clients. CVE-2026-0295 (CVSS 4.1): Fixes a race condition leading to local privilege escalation on macOS endpoints. Patches for several GlobalProtect app flaws on the 6.0 branch carry an estimated availability date of August 31, 2026, indicating remediation efforts remain ongoing for legacy clients. CVE Identifier Component / Product CVSS Score Vulnerability Type & Scope Patch Status / ETA CVE-2026-0301 PAN-OS URL Filtering / Prisma Access 1.7 Information Disclosure Patched / Cloud Remediated CVE-2026-0299 GlobalProtect App (Desktop) 5.9 Local Privilege Escalation Patched (Branch 6.0 ETA Aug 31) CVE-2026-0298 GlobalProtect Windows PLAP 5.2 Local Code Execution Patched CVE-2026-0297 GlobalProtect App (Mobile/Desktop) 5.2 UDP Handshake Buffer Overflow Fixed in 6.3.5+ CVE-2026-0294 Prisma Access Agent (Win/macOS) 6.0 Local Privilege Escalation Pending (ETA Aug 20, 2026) CVE-2026-0293 Prisma Access Agent (Windows) 5.6 Anti-Tamper Protection Bypass Pending (ETA Aug 20, 2026) PAN-SA-2026-0011 Prisma Browser (< 148.18.4.217) 7.2 Chromium Rollup Vulnerabilities Fixed in 150.49.8.187+ Prisma Access Agent was subject to four separate security disclosures: CVE-2026-0294 (CVSS 6.0): A local privilege escalation vulnerability affecting Windows and macOS with a fix ETA of August 20. CVE-2026-0293 (CVSS 5.6): An anti-tamper protection bypass on Windows with an August 20 fix ETA. CVE-2026-0292 (CVSS 2.1): A local security inspection bypass on Windows sharing the August 20 timeline. CVE-2026-0291 (CVSS 1.1): An authenticated file deletion flaw on Linux, already patched in version 26.2.2. Separately, Palo Alto Networks issued advisory PAN-SA-2026-0011, addressing Chromium vulnerabilities in Prisma Browser builds prior to 148.18.4.217. With a CVSS score of 7.2, this is the highest risk score in the August update cycle. Organizations using Prisma Browser should prioritize updating to version 150.49.8.187 or later. While none of the flaws disclosed in this cycle are currently flagged as actively exploited, the volume of GlobalProtect and Prisma Access Agent fixes underscores endpoint exposure. Administrators should prioritize updating internet-facing PAN-OS management interfaces and URL filtering policies, followed by desktop VPN clients on Windows and macOS, where privilege escalation vulnerabilities intersect. [Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now Tags cyber security news vulnerability Copy URL Linkedin Twitter ReddIt Telegram Guru Baranhttps://cybersecuritynews.com Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security Funding Mindgard Raises $30 Million to Tackle AI’s Fastest-Growing Attack Surface Cyber Security News China-linked Hackers Using AI Agents to Attack Taiwan Government Websites Cyber Security News Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code Cyber Security WhatsApp Unveils New Scam Alert Feature to Protect Users from Social Engineering Attacks Cyber Attack News Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗