CVE-2026-0301: Palo Alto Networks Cloud Ngfw
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
Affected products
- Palo Alto Networks Cloud Ngfw: affected versions not specified
- Palo Alto Networks PAN-OS: from 10.2.0, before 10.2.8 (fixed in 10.2.8); from 11.1.0, before 11.1.16 (fixed in 11.1.16); version 11.1.16 only
- Palo Alto Networks Prisma Access: before 6.0.0 (fixed in 6.0.0)
Published 2026-08-13. Last modified 2026-08-28.