Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.7

CVE-2026-0284: Palo Alto Networks PAN-OS: Large Scale VPN Data Corruption Risk

CVE-2026-0284 CVE-2026-0284
Summary

A vulnerability in Palo Alto Networks PAN-OS software affects its Large Scale VPN feature. This means an attacker with access to your network could potentially steal or alter sensitive data. To stay safe, update your PAN-OS software as soon as possible.

What to do
  • Update palo alto networks pan-os to version 12.1.8.
Affected software
VendorProductAffected versions
palo alto networks cloud ngfw All versions
palo alto networks pan-os < 12.1.4-h8
Fix: upgrade to 12.1.8
palo alto networks prisma access All versions
paloaltonetworks pan-os >= 10.2.0, < 10.2.7
>= 10.2.8, < 10.2.10
>= 10.2.11, < 10.2.13
>= 10.2.14, < 10.2.16
10.2.7
10.2.10
10.2.13
10.2.16
10.2.17
10.2.18
>= 11.1.0, < 11.1.4
>= 11.1.8, < 11.1.10
>= 11.1.11, < 11.1.13
>= 11.1.14, < 11.1.16
11.1.4
11.1.5
11.1.6
11.1.10
11.1.13
>= 11.2.0, < 11.2.4
>= 11.2.5, < 11.2.7
>= 11.2.8, < 11.2.10
>= 11.2.11, < 11.2.13
11.2.4
11.2.7
11.2.10
>= 12.1.2, < 12.1.4
>= 12.1.5, < 12.1.7
12.1.4
12.1.7
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Original title
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML co...
Original description
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
nvd CVSS4.0 4.7
Vulnerability type
CWE-74 Injection
Published: 9 Jul 2026 · Updated: 22 Jul 2026 · First seen: 9 Jul 2026