CVE Tools

Pan-os

269 CVEs tracked. 14 of them are in CISA KEV.

This hub aggregates every CVE we track for Pan-os, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Pan-os CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Pan-os CVEs per month
MonthCVEs
2024-102
2024-1110
2024-121
2025-015
2025-023
2025-033
2025-046
2025-054
2025-063
2025-070
2025-081
2025-090
2025-102
2025-111
2025-120
2026-011
2026-022
2026-030
2026-040
2026-0510
2026-064
2026-0710
2026-081
2026-093

Severity

How the 269 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical4015%
  • High10238%
  • Medium11242%
  • Low125%

Latest CVEs

The 15 most recently published vulnerabilities affecting Pan-os.

  1. CVE-2026-0308PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface—
  2. CVE-2026-0309PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration—
  3. CVE-2026-0310PAN-OS: Buffer Overflow Vulnerability via XML Processing—
  4. CVE-2026-0301PAN-OS: Information Disclosure Vulnerability in URL Filtering7.5
  5. CVE-2026-0279PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities6.1
  6. CVE-2026-0280PAN-OS: IPv6 Firewall Policy Bypass7.2
  7. CVE-2026-0281PAN-OS: Information Disclosure Vulnerability in Management Web Interface7.1
  8. CVE-2026-0282PAN-OS: File Deletion Vulnerability in Management Web Interface6.5
  9. CVE-2026-0283PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)7.2
  10. CVE-2026-0284PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)9.9
  11. CVE-2026-0285PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface4.9
  12. CVE-2026-0286PAN-OS: Authenticated Command Injection in CLI7.2
  13. CVE-2026-0287PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing7.5
  14. CVE-2026-0288PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent7.5
  15. CVE-2026-0273PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store