CVE-2026-0277: Palo Alto Networks Prisma Access Agent

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.

Affected products

Published 2026-07-09. Last modified 2026-07-16.