CVE-2026-0244: Palo Alto Networks Prisma SD-WAN
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.
Affected products
- Palo Alto Networks Prisma SD-WAN: from 6.3.1, before 6.3.6 (fixed in 6.3.6); from 6.4.1, before 6.4.3 (fixed in 6.4.3); from 6.5.1, before 6.5.3 (fixed in 6.5.3); version 6.3.6 only; version 6.4.3 only; version 6.5.3 only
Published 2026-05-13. Last modified 2026-07-14.