CVE-2026-0304: Palo Alto Networks Cortex Xdr Broker Vm
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Affected products
- Palo Alto Networks Cortex Xdr Broker Vm: from 20.0.96, before 32.0.52 (fixed in 32.0.52)
Published 2026-09-10. Last modified 2026-09-11.