Palo Alto Networks released its scheduled August 2026 security update on August 12, addressing 11 new vulnerabilities in its product portfolio. The patches cover a range of products, including the PAN-OS firewall operating system, the GlobalProtect VPN client, Prisma Access Agent, and Prisma Browser. The update did not include any critical-severity vulnerabilities, with the most severe flaw receiving a CVSS score of 7.2. The addressed vulnerabilities could lead to conditions such as information disclosure, local privilege escalation, and buffer overflows. A significant portion of the fixes apply to the widely deployed GlobalProtect agent, emphasizing the importance of keeping endpoint software updated.
The August 12, 2026, bulletin includes fixes for 11 CVEs. While none are critical, they represent a risk that should be addressed through patching.
While no active exploitation has been reported for these specific vulnerabilities, they present a potential risk to organizations using the affected products. The privilege escalation flaws in the GlobalProtect client (CVE-2026-0299) are notable, as they could allow a local attacker or malicious code already on an endpoint to gain higher-level permissions. Buffer overflows like CVE-2026-0297 could lead to denial of service or potential code execution. Although the overall severity is moderate, the widespread deployment of these products, especially the GlobalProtect VPN client, means that timely patching is a crucial defensive measure to reduce the attack surface.
Palo Alto Networks has released software updates to address all the vulnerabilities mentioned in the bulletin. For cloud-hosted services like Cloud NGFW and Prisma Access, the fixes have already been applied by the vendor. Customers with on-premise firewalls and those managing endpoint clients (GlobalProtect, Prisma Browser) are responsible for applying the updates.
Customers can download the updated software versions from the Palo Alto Networks Customer Support Portal. It is recommended to follow the release notes for each product for specific installation instructions and to test the updates in a non-production environment before rolling them out to the entire organization if possible.
The following indicators could help identify unpatched systems or active exploitation:
GlobalProtect.exePanGPS.exeApplying the vendor-supplied patches is the most direct and effective way to mitigate these vulnerabilities.
Mapped D3FEND Techniques:
Palo Alto Networks publishes its August 2026 security bulletin.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.