SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-0279

MEDIUM · CVSS 6.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Multiple cross-site scripting vulnerabilities in Palo Alto Networks' PAN-OS software, specifically within the User-ID™ Authentication Portal and GlobalProtect™ features, allow unauthenticated users to execute malicious JavaScript payloads. Organizations using PA-Series, VM-Series firewalls, and Panorama should prioritize addressing this issue, particularly by restricting access to the affected services to trusted internal IP addresses as per best practices. While the risk is moderate, failure to mitigate these vulnerabilities could lead to unauthorized access and potential exploitation of sensitive information.

CVE
CVE-2026-0279
Severity
MEDIUM
CVSS
6.1
EPSS
0.32%
Palo Alto PAN-OS Java

Original NVD Description

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)