Palo Alto Networks Patches 11 Flaws in PAN-OS, GlobalProtect

Palo Alto Networks Patches 11 Flaws in Monthly Update

MEDIUM
August 13, 2026
3m read
Patch ManagementVulnerability

Related Entities

Organizations

Products & Tech

PAN-OSGlobalProtectPrisma AccessPrisma Browser

CVE Identifiers

CVE-2026-0301
LOW
CVSS:1.7
CVE-2026-0299
MEDIUM
CVSS:5.9
CVE-2026-0298
MEDIUM
CVSS:5.2
CVE-2026-0297
MEDIUM
CVSS:5.2

Full Report

Executive Summary

Palo Alto Networks released its scheduled August 2026 security update on August 12, addressing 11 new vulnerabilities in its product portfolio. The patches cover a range of products, including the PAN-OS firewall operating system, the GlobalProtect VPN client, Prisma Access Agent, and Prisma Browser. The update did not include any critical-severity vulnerabilities, with the most severe flaw receiving a CVSS score of 7.2. The addressed vulnerabilities could lead to conditions such as information disclosure, local privilege escalation, and buffer overflows. A significant portion of the fixes apply to the widely deployed GlobalProtect agent, emphasizing the importance of keeping endpoint software updated.

Vulnerabilities Addressed

The August 12, 2026, bulletin includes fixes for 11 CVEs. While none are critical, they represent a risk that should be addressed through patching.

  • Highest Rated (CVSS 7.2): An advisory (PAN-SA-2026-0011) addresses Chromium vulnerabilities within the Prisma Browser. Customers are advised to update to version 150.49.8.187 or later.
  • GlobalProtect App Vulnerabilities: The endpoint VPN client received patches for six vulnerabilities:
    • CVE-2026-0299 (CVSS 5.9): Multiple local privilege escalation flaws on Linux, macOS, and Windows versions.
    • CVE-2026-0297 (CVSS 5.2): A buffer overflow vulnerability affecting mobile versions for iOS, Android, and Chrome OS.
    • Other less severe flaws were also addressed.
  • PAN-OS Vulnerability:
    • CVE-2026-0301 (CVSS 1.7): A low-severity information disclosure flaw in the URL Filtering component of PAN-OS, Cloud NGFW, and Prisma Access.

Affected Products

  • PAN-OS: Multiple versions including 12.1, 11.2, 11.1, 10.2.
  • GlobalProtect App: Versions 6.3, 6.2, 6.0 for Windows, macOS, Linux, iOS, Android, and Chrome OS.
  • Prisma Access Agent
  • Prisma Browser: Versions prior to 148.18.4.217.
  • Cloud NGFW and Prisma Access

Impact Assessment

While no active exploitation has been reported for these specific vulnerabilities, they present a potential risk to organizations using the affected products. The privilege escalation flaws in the GlobalProtect client (CVE-2026-0299) are notable, as they could allow a local attacker or malicious code already on an endpoint to gain higher-level permissions. Buffer overflows like CVE-2026-0297 could lead to denial of service or potential code execution. Although the overall severity is moderate, the widespread deployment of these products, especially the GlobalProtect VPN client, means that timely patching is a crucial defensive measure to reduce the attack surface.

Patch Details

Palo Alto Networks has released software updates to address all the vulnerabilities mentioned in the bulletin. For cloud-hosted services like Cloud NGFW and Prisma Access, the fixes have already been applied by the vendor. Customers with on-premise firewalls and those managing endpoint clients (GlobalProtect, Prisma Browser) are responsible for applying the updates.

Deployment Priority

  1. Internet-Facing Systems: Prioritize patching of PAN-OS firewalls that have management interfaces exposed (though this is not a recommended practice).
  2. Endpoints: Deploy the updated GlobalProtect App and Prisma Browser versions to all corporate endpoints (laptops, desktops, mobile devices) as soon as possible to mitigate the local privilege escalation and buffer overflow risks.
  3. Internal Systems: Schedule patching for internal firewall segments as part of regular maintenance.

Installation Instructions

Customers can download the updated software versions from the Palo Alto Networks Customer Support Portal. It is recommended to follow the release notes for each product for specific installation instructions and to test the updates in a non-production environment before rolling them out to the entire organization if possible.

Cyber Observables — Hunting Hints

The following indicators could help identify unpatched systems or active exploitation:

Type
File Name
Value
GlobalProtect.exe
Description
Check the file version of the GlobalProtect executable on endpoints to identify systems that are running a vulnerable version.
Type
Log Source
Value
PAN-OS System Logs
Description
Monitor for unexpected service restarts or error messages related to the URL Filtering component, which could indicate issues related to CVE-2026-0301.
Type
Process Name
Value
PanGPS.exe
Description
On Windows, monitor the GlobalProtect service process for crashes or anomalous behavior that could indicate an attempt to exploit a buffer overflow.

Timeline of Events

1
August 12, 2026
Palo Alto Networks publishes its August 2026 security bulletin.
2
August 13, 2026
This article was published

MITRE ATT&CK Mitigations

Applying the vendor-supplied patches is the most direct and effective way to mitigate these vulnerabilities.

Mapped D3FEND Techniques:

Timeline of Events

1
August 12, 2026

Palo Alto Networks publishes its August 2026 security bulletin.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Palo Alto NetworksPAN-OSGlobalProtectPatch ManagementVulnerability

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.