SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-0284

CRITICAL · CVSS 9.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS allows unauthenticated attackers with network access to inject malicious XML, which could result in information disclosure or corruption of internal LSVPN satellite data. Organizations using affected versions of PAN-OS should prioritize patching this critical vulnerability to mitigate the risk of exploitation. This is particularly crucial for enterprises relying on LSVPN for secure communications.

CVE
CVE-2026-0284
Severity
CRITICAL
CVSS
9.9
EPSS
0.27%
Palo Alto PAN-OS

Original NVD Description

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)