Advisory Date: 13 August 2026
Threat Category: Vulnerability Management / Network Security
Severity: Moderate
Affected Technologies: PAN-OS, GlobalProtect App, Prisma Access Agent, Prisma Browser
Vulnerabilities Disclosed: 11
Highest Reported CVSS: 7.2
Executive Summary
Palo Alto Networks has released its August 2026 security update addressing 11 newly disclosed vulnerabilities across PAN-OS, GlobalProtect, Prisma Access Agent and Prisma Browser, alongside a Chromium update rollup.
The vulnerabilities range from information disclosure and buffer overflow vulnerabilities to local privilege escalation, certificate validation bypass, security inspection bypass and anti-tamper protection bypass. CVSS scores range from 1.1 to 7.2, with the highest-rated issue affecting Prisma Browser.
While these vulnerabilities have not been actively exploited, the exposure is operationally significant because the affected products sit at different layers of an enterprise environment. PAN-OS protects network infrastructure, GlobalProtect provides remote connectivity, Prisma Access Agent provides security and access controls on endpoints, while Prisma Browser introduces a browser-based attack surface. Internet-facing PAN-OS infrastructure, remote-access clients and security agents should be identified and prioritised for remediation, particularly where older versions remain in use.
What Was Affected?
1. PAN-OS and URL Filtering
The infrastructure-focused vulnerability, CVE-2026-0301, is an information disclosure vulnerability affecting PAN-OS URL Filtering. It affects Cloud NGFW and multiple PAN-OS branches, including 12.1, 11.2, 11.1 and 10.2, as well as Prisma Access environments hosted on AWS and Azure. Although the vulnerability carries a relatively low CVSS score of 1.7, the affected technology is security infrastructure. An issue within a firewall or security-control layer should therefore not automatically be deprioritised solely because its numerical severity is low. Palo Alto Networks has already remediated the relevant Cloud NGFW and public-cloud Prisma Access instances, while fixes are available for affected PAN-OS releases.
2. GlobalProtect: The Most Concentrated Exposure
GlobalProtect accounts for the largest concentration of vulnerabilities in this update. The disclosed issues affect desktop clients across Windows, macOS and Linux, with individual vulnerabilities involving local privilege escalation, code execution, buffer overflow, certificate validation and race-condition weaknesses. Of particular interest is CVE-2026-0299, rated CVSS 5.9, which addresses multiple local privilege escalation vulnerabilities affecting GlobalProtect 6.3, 6.2 and 6.0 on Windows, macOS and Linux. There is also CVE-2026-0298, a Windows-specific code execution vulnerability affecting the Pre-Logon Access Provider (PLAP), and CVE-2026-0297, a buffer overflow occurring during the UDP tunnel handshake process. The latter affects versions prior to 6.3.5 across specified mobile and desktop environments.
Why these matter
GlobalProtect is commonly used to provide remote access into corporate environments. A compromised endpoint running a vulnerable client could therefore represent more than an isolated workstation issue. For example, an attacker who has already obtained a foothold on an endpoint may attempt to exploit a local privilege escalation vulnerability to move from a lower-privileged user context to a more powerful account. This makes GlobalProtect vulnerabilities particularly relevant to organisations with:
- Large remote-working populations;
- Privileged users connecting through VPN;
- BYOD or unmanaged endpoint exposure;
- Shared or legacy GlobalProtect installations; and
- Endpoints that cannot be rapidly patched.
The supplied sources indicate that some fixes for the GlobalProtect 6.0 branch are expected by 31 August 2026, so organisations should maintain a remediation tracker for systems that cannot yet be patched.
3. Prisma Access Agent
Four vulnerabilities affected Prisma Access Agent. These include:
- CVE-2026-0294 (CVSS 6.0): Local privilege escalation affecting Windows and macOS.
- CVE-2026-0293 (CVSS 5.6): Anti-tamper protection bypass on Windows.
- CVE-2026-0292 (CVSS 2.1): Local security inspection bypass on Windows.
- CVE-2026-0291 (CVSS 1.1): Authenticated file deletion affecting Linux.
The first three issues are particularly relevant from a defensive standpoint because they concern the ability to gain additional privileges or bypass security protections. Fixes for CVE-2026-0294, CVE-2026-0293 and CVE-2026-0292 are to be expected around 20 August 2026, while CVE-2026-0291 has already been addressed in version 26.2.2.
4. Prisma Browser: Highest-Rated Issue
The highest-rated vulnerability in the August update is PAN-SA-2026-0011, associated with Chromium vulnerabilities affecting Prisma Browser versions before 148.18.4.217. The issue carries a CVSS score of 7.2, making it the highest-rated vulnerability identified in this update cycle. Organisations should update Prisma Browser to 150.49.8.187 or later.
Recommendations
- Identify versions affected by the August 2026 vulnerabilities.
- Correlate endpoint and VPN telemetry for vulnerable systems until remediation is confirmed.
- Prioritise Prisma Browser systems requiring 150.49.8.187 or later.
- Prioritise browser updates across corporate endpoints.
- Pay particular attention to endpoints used for privileged administration, financial operations and access to sensitive corporate applications.

.jpeg)

.jpeg)
.jpeg)


.png)

.png)
.png)