CVE-2025-0126: Palo Alto Networks Cloud Ngfw

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS® management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma® Access instances are proactively patched.

Affected products

  • Palo Alto Networks Cloud Ngfw
  • Palo Alto Networks PAN-OS: from 11.2.0, before 11.2.3 (fixed in 11.2.3); from 11.1.0, before 11.1.5 (fixed in 11.1.5); from 11.0.0, before 11.0.6 (fixed in 11.0.6); from 10.2.0, before 10.2.10-h6 (fixed in 10.2.10-h6); from 10.1.0, before 10.1.14-h11 (fixed in 10.1.14-h11)
  • Palo Alto Networks Prisma Access: from 10.2.0, before 10.2.4-h36 (fixed in 10.2.4-h36); from 11.2.0, before 11.2.4-h5 (fixed in 11.2.4-h5)

Published 2025-04-11. Last modified 2026-06-17.