Palo Alto Networks has issued emergency patches to fix 13 critical vulnerabilities in its products, including multiple flaws that could allow attackers to execute arbitrary code on firewalls. The company’s software is widely used by organizations to protect their networks from cyber threats.
The most severe vulnerability, CVE-2026-0288, affects the PAN-OS software that powers Palo Alto Networks’ firewalls and can be exploited by an unauthenticated attacker to cause a denial-of-service (DoS) condition or execute arbitrary code. This is particularly concerning because it requires no prior authentication or privileges, making it easier for attackers to exploit.
However, security experts point out that the risk of exploitation is mitigated when organizations follow best practices and limit access to the User-ID Terminal Server Agent (TSA) to trusted internal IP addresses. Additionally, Palo Alto Networks notes that seven of the newly patched flaws have a medium severity rating, but still pose a significant threat if exploited.
These vulnerabilities can be used to execute arbitrary OS commands as root, make unauthorized requests from the firewall to internal services, obtain information, and bypass authentication controls. Some of these issues require the attacker to be authenticated with admin privileges, while others can be exploited by an unauthenticated user. The company also warns that five medium-severity vulnerabilities impact Prisma Access Agent and can be used for man-in-the-middle (MitM) attacks.
The patches also address several lower-severity vulnerabilities that could allow privilege escalation, code execution via cross-site scripting (XSS) attacks, firewall policy bypassing, file deletion, and information disclosure. While Palo Alto Networks states it’s not aware of any attacks exploiting these vulnerabilities, the company notes that its products have been targeted by threat actors in the past.
It’s worth noting that several of the newly patched flaws were discovered by external researchers, while others were identified through internal vulnerability discovery efforts, which the company credits to its use of artificial intelligence (AI). This highlights the importance of using AI-powered tools to identify vulnerabilities and stay ahead of emerging threats.
In light of these patches, organizations that rely on Palo Alto Networks products should prioritize installing the latest updates to ensure their firewalls are protected against potential attacks. While this may require some technical effort, it’s a crucial step in maintaining the security of their networks and protecting sensitive data from cyber threats.
Source: SecurityWeek — 2026-07-09