CVE-2025-0121: Palo Alto Networks Cortex Xdr Agent
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.
Affected products
- Palo Alto Networks Cortex Xdr Agent: from 8.6.0, before 8.6.1 (fixed in 8.6.1); from 8.5.0, before 8.5.2 (fixed in 8.5.2); from 8.3-CE, before 8.3.101-CE HF (fixed in 8.3.101-CE HF); from 7.9-CE, before 7.9.103-CE HF (fixed in 7.9.103-CE HF)
Published 2025-04-11. Last modified 2026-06-17.