PT-2026-56909 · Palo Alto Networks · Pa-Series+4

CVE-2026-0279

·

Published

2026-07-08

·

Updated

2026-07-09

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PAN-OS (affected versions not specified)
Description Multiple cross-site scripting issues exist in the User-ID Authentication Portal, GlobalProtect gateway/portal features, and Clientless VPN. These flaws allow an unauthenticated remote attacker to store or execute malicious JavaScript payloads by exploiting a lack of proper web page structure protection. This affects PA-Series and VM-Series firewalls, as well as Panorama virtual and M-Series, and Prisma Access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict management interface and User-ID Authentication Portal access to trusted internal IP addresses.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09551
CVE-2026-0279

Affected Products

Pa-Series
Pan-Os
Panorama
Prisma Access
Vm Series