Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.7
CVE-2026-0284: Palo Alto Networks PAN-OS: Large Scale VPN Data Corruption Risk
CVE-2026-0284
CVE-2026-0284
Summary
A vulnerability in Palo Alto Networks PAN-OS software affects its Large Scale VPN feature. This means an attacker with access to your network could potentially steal or alter sensitive data. To stay safe, update your PAN-OS software as soon as possible.
What to do
- Update palo alto networks pan-os to version 12.1.8.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| palo alto networks | cloud ngfw | All versions |
| palo alto networks | pan-os |
< 12.1.4-h8 Fix: upgrade to 12.1.8
|
| palo alto networks | prisma access | All versions |
| paloaltonetworks | pan-os |
>= 10.2.0, < 10.2.7 >= 10.2.8, < 10.2.10 >= 10.2.11, < 10.2.13 >= 10.2.14, < 10.2.16 10.2.7 10.2.10 10.2.13 10.2.16 10.2.17 10.2.18 >= 11.1.0, < 11.1.4 >= 11.1.8, < 11.1.10 >= 11.1.11, < 11.1.13 >= 11.1.14, < 11.1.16 11.1.4 11.1.5 11.1.6 11.1.10 11.1.13 >= 11.2.0, < 11.2.4 >= 11.2.5, < 11.2.7 >= 11.2.8, < 11.2.10 >= 11.2.11, < 11.2.13 11.2.4 11.2.7 11.2.10 >= 12.1.2, < 12.1.4 >= 12.1.5, < 12.1.7 12.1.4 12.1.7 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
Original title
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML co...
Original description
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
nvd CVSS4.0
4.7
Vulnerability type
CWE-74
Injection
Published: 9 Jul 2026 · Updated: 22 Jul 2026 · First seen: 9 Jul 2026