Multiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)
Multiple vulnerabilities have been discovered in Palo Alto Networks products, including Checkov, Cloud NGFW, Cortex XDR Broker, GlobalProtect App, PAN-OS, Prisma Access Agent, and Prisma Browser. These vulnerabilities allow for remote code execution, denial-of-service attacks, and cross-site scripting (XSS). Users are advised to refer to Palo Alto Networks' security bulletin for detailed information and to apply the necessary patches immediately.
A security bulletin released by CERT-FR details multiple vulnerabilities affecting Palo Alto Networks products. These vulnerabilities range from denial-of-service attacks to remote code execution and XSS. Specifically, the vulnerabilities impact Checkov by Prisma Cloud versions 3.2.x prior to 3.2.532, Cloud NGFW across all versions, Cortex XDR Broker versions prior to 32.0.52, GlobalProtect App for Android, ChromeOS, iOS, and versions 6.0 prior to 6.0.15, 6.2 prior to 6.2.8-h14, and 6.3 prior to 6.3.3-h15, PAN-OS versions 11.1.16-hx prior to 11.1.16-h2, 11.1.4-hx prior to 11.1.4-h36, 11.2.13-hx prior to 11.2.13-h2, 11.2.4-hx prior to 11.2.4-h21, 12.1.4-hx prior to 12.1.4-h10, and versions prior to 12.1.10, 12.2.x prior to 12.2.3, PAN-OS versions prior to 10.2.7-h37, Prisma Access Agent versions prior to 26.2 for Windows and 26.3 for Linux, Prisma Access versions prior to 10.2.0 without the latest security patches, Prisma Browser versions prior to 151.26.5.170, and PAN-SA-2026-0012. The bulletin provides CVE identifiers for each vulnerability, including CVE-2026-0302, CVE-2026-0303, CVE-2026-0304, CVE-2026-0305, CVE-2026-0306, CVE-2026-0307, CVE-2026-0308, CVE-2026-0309, CVE-2026-0310, CVE-2026-76020, CVE-2026-76022, CVE-2026-76038, CVE-26-76046, CVE-2026-76047, CVE-2026-79016, CVE-2026-79032, CVE-2026-79118, CVE-2026-79195, CVE-2026-79282, CVE-2026-79286, CVE-2026-79290, CVE-2026-79293, CVE-2026-84348, CVE-2026-84350, CVE-2026-84351, CVE-2026-84357, CVE-2026-84358, and CVE-2026-84359. Users are strongly advised to consult the Palo Alto Networks security bulletin for detailed remediation steps and to apply the latest patches immediately to mitigate these risks.