Thursday , August 13 2026

Palo Alto Patches 11 New flaws Across PAN-OS, GlobalProtect, and Prisma Access

Palo Alto Networks shared its security bulletin revealing 11 new issues that impact PAN-OS, the GlobalProtect App, Prisma Access Agent, and Prisma Browser. There is also a monthly update for Chromium.

The patch batch covers flaws with information leaks, getting extra system rights, buffer overflow, skipping certificate checks, and bypassing security measures.

Palo Alto Patches 11 New flaws Across PAN-OS, GlobalProtect, and Prisma Access

Palo Alto Networks shared its security bulletin revealing 11 new issues that impact PAN-OS, the GlobalProtect App, Prisma Access Agent,...
Read More
Palo Alto Patches 11 New flaws Across PAN-OS, GlobalProtect, and Prisma Access

CVE-2026-20349, CVE-2026-68820
Cisco and Windows patched zero days exploited in attack

Cisco warns customers that it has fixed a serious security hole in firewalls using Secure Firewall Adaptive Security Appliance (ASA)...
Read More
CVE-2026-20349, CVE-2026-68820  Cisco and Windows patched zero days exploited in attack

Microsoft Patch 394 Flaws, Including 3 Zero-Days

Microsoft announced fixes for 394 CVEs on Tuesday, including a serious flaw that has been used by hackers as a...
Read More
Microsoft Patch 394 Flaws, Including 3 Zero-Days

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else's device in a live meeting...
Read More
AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

Hacker Actively Exploit SonicWall and SharePoint Flaws

The CISA in the U.S. has added two important SonicWall SMA1000 flaws—CVE-2026-15409 and CVE-2026-15410-to its list of Known Exploited Vulnerabilities...
Read More
Hacker Actively Exploit SonicWall and SharePoint Flaws

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service,...
Read More
Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real...
Read More
Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Android users are reminded that a known app store listing can hold a money threat. Researchers found harmful loaders on...
Read More
Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV...
Read More
Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

A group of almost 800 harmful packages was added to the npm registry in a new effort to spread malware...
Read More
Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

Severity scores go from a low 1.1 to a moderate 7.2 on the CVSS scale. This means that none of the new issues are very serious in this release. Security teams watching PAN-OS weaknesses should check endpoint risks in all company areas.

Palo Alto Networks Patches 11 New Flaws

The main infrastructure issue, CVE-2026-0301, is a low-risk (CVSS 1.7) flaw that lets information leak in PAN-OS URL Filtering. It affects Cloud NGFW and several PAN-OS versions like 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access set up on AWS and Azure.

Fixes are ready for the affected PAN-OS 11.1 and 10.2 versions, and Palo Alto Networks has already fixed the Cloud NGFW and public-cloud Prisma Access systems. Organizations should check the release tables in the Palo Alto Networks Security Advisories. This will help them make sure all firewall management interfaces are updated.

The GlobalProtect App had the most fixes this month, with six different CVEs reported:

CVE-2026-0299 (CVSS 5.9): Addresses multiple local privilege escalation flaws across GlobalProtect 6.3, 6.2, and 6.0 on Linux, macOS, and Windows; mobile builds (iOS, Android, Chrome OS) remain unaffected.
CVE-2026-0298 (CVSS 5.2): Resolves a code execution vulnerability specific to the Windows Pre-Logon Access Provider (PLAP) component.
CVE-2026-0297 (CVSS 5.2): Fixes a buffer overflow triggered during the UDP tunnel handshake process, impacting iOS, Android, and Chrome OS versions prior to 6.3.5.
CVE-2026-0296 (CVSS 4.5): Mitigates an improper certificate validation bypass affecting desktop clients.
CVE-2026-0295 (CVSS 4.1): Fixes a race condition leading to local privilege escalation on macOS endpoints.

Patches for some GlobalProtect app flaws on version 6.0 are expected to be ready by August 31, 2026, showing that work is still being done for older clients.

CVE Identifier Component / Product CVSS Score Vulnerability Type & Scope Patch Status / ETA
CVE-2026-0301 PAN-OS URL Filtering / Prisma Access 1.7 Information Disclosure Patched / Cloud Remediated
CVE-2026-0299 GlobalProtect App (Desktop) 5.9 Local Privilege Escalation Patched (Branch 6.0 ETA Aug 31)
CVE-2026-0298 GlobalProtect Windows PLAP 5.2 Local Code Execution Patched
CVE-2026-0297 GlobalProtect App (Mobile/Desktop) 5.2 UDP Handshake Buffer Overflow Fixed in 6.3.5+
CVE-2026-0294 Prisma Access Agent (Win/macOS) 6.0 Local Privilege Escalation Pending (ETA Aug 20, 2026)
CVE-2026-0293 Prisma Access Agent (Windows) 5.6 Anti-Tamper Protection Bypass Pending (ETA Aug 20, 2026)
PAN-SA-2026-0011 Prisma Browser (< 148.18.4.217) 7.2 Chromium Rollup Vulnerabilities Fixed in 150.49.8.187+

Prisma Access Agent was subject to four separate security disclosures:

CVE-2026-0294 (CVSS 6.0): A local privilege escalation vulnerability affecting Windows and macOS with a fix ETA of August 20.
CVE-2026-0293 (CVSS 5.6): An anti-tamper protection bypass on Windows with an August 20 fix ETA.
CVE-2026-0292 (CVSS 2.1): A local security inspection bypass on Windows sharing the August 20 timeline.
CVE-2026-0291 (CVSS 1.1): An authenticated file deletion flaw on Linux, already patched in version 26.2.2.

Palo Alto Networks released alert PAN-SA-2026-0011 about issues in Chromium for Prisma Browser versions before 148.18.4.217. It has a CVSS score of 7.2, which is the highest risk in the August update.

Organizations using Prisma Browser should prioritize updating to version 150.49.8.187 or later.

Administrators should focus on updating the PAN-OS management interfaces and URL filtering rules that are exposed to the internet. Next, they should update desktop VPN clients on Windows and macOS, where there are issues with privilege escalation.

Check Also

Gentlemen

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer …