← All Advisories

Palo Alto Networks Cloud NGFW and Prisma Access Use of Uninitialized Resource Allows a Network-Based Attacker to Access Sensitive Information

Last refreshed2026-09-27

Status: EXPLOITED  |  Advisory ID: CVE-2026-0301

Key Details

CVECVE-2026-0301
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsPalo Alto Networks Cloud NGFW, Palo Alto Networks Prisma Access, and Palo Alto Networks PAN-OS
Exploitation statusPalo Alto Networks is not aware of any malicious exploitation of this issue.
Classified asCWE-908 (Use of Uninitialized Resource)
Exploitation prediction (EPSS)0.32% probability of exploitation in the next 30 days (22% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksCloud NGFW
Palo Alto NetworksPrisma Access
Palo Alto NetworksPAN-OS
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.

What to Do

PAN-OS 12.1/11.2: no action needed. PAN-OS 11.1: upgrade to 11.1.16-h1 or later. PAN-OS 10.2: upgrade to 10.2.8 or 11.1.16-h1 or later. Older unsupported PAN-OS versions: upgrade to a supported fixed version. Cloud NGFW customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0301
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0301
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0301