CVE-2020-1991: Palo Alto Networks Traps

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on Windows. This issue does not affect Cortex XDR 7.0. This issue does not affect Traps for Linux or MacOS.

Affected products

  • Palo Alto Networks Traps: from 5.0, before 5.0.8 (fixed in 5.0.8); from 6.1, before 6.1.4 (fixed in 6.1.4)

Published 2020-04-08. Last modified 2026-06-17.