Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4172 articles · 197414 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-0279EXPLOITEDPATCHED
palo alto networks · cloud ngfw

PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

Description

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.

Affected Products

VendorProductVersions
palo alto networkscloud ngfw12.1.0, 11.2.0, 11.1.0, 10.2.0, 12.1.0, 11.2.0, 10.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
palo alto networksprisma accessmitre_affected90%
palo alto networkspan-osmitre_affected90%

References

  • https://security.paloaltonetworks.com/CVE-2026-0279(vendor-advisory)

Related News (3 articles)

Tier C
VulDB47d ago
CVE-2026-0279 | Palo Alto Captive Portal/Clientless VPN/GlobalProtect cross site scripting
→ No new info (linked only)
Tier B
BSI Advisories47d ago
[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR47d ago
Multiples vulnérabilités dans les produits Palo Alto Networks (09 juillet 2026)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
All12.1.811.2.1311.1.1610.2.18-h8
CWECWE-79
PublishedJul 9, 2026
Last enriched47d agov2
Trending Score0
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-0288
PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Trending: 1
NONECVE-2026-0284EXP
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
NONECVE-2026-0278
Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
NONECVE-2026-0275
Prisma Browser: Local Privilege Escalation on macOS
NONECVE-2026-0286EXP
PAN-OS: Authenticated Command Injection in CLI

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 9, 2026
Discovered by ZDM
Jul 9, 2026
Updated: description, severity, activelyExploited
Jul 9, 2026
Actively Exploited
Aug 11, 2026
Patch Available
Aug 11, 2026

Version History

v2
Last enriched 47d ago
v2Tier C47d ago

Updated description with new details, changed product to 'captive portal', updated severity to HIGH, and marked as actively exploited.

descriptionseverityactivelyExploited
via VulDB
v147d ago

Initial creation