CVE-2026-4761: Codra Panorama Collaborative Operation & Execution
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt.
Affected products
- Codra Panorama Collaborative Operation & Execution: version 25.00.004 only
- Codra Panorama Com: version 25.00.004 only
- Codra Panorama e2: version 25.00.004 only
- Codra Panorama h2: version 25.00.004 only
Published 2026-03-25. Last modified 2026-06-17.