CVE-2026-0268: Palo Alto Networks Prisma Access Agent
Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
Affected products
- Palo Alto Networks Prisma Access Agent: from 25.7, before 26.2.1 (fixed in 26.2.1)
Published 2026-06-10. Last modified 2026-07-23.