Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerability

Palo Alto Networks Patches Cortex XDR and Prisma Browser Vulnerabilities

Updated 3mo agoFirst seen Mar 12, 20266 sources

Palo Alto Networks published security advisories addressing multiple vulnerabilities affecting Cortex XDR components and Prisma Browser, including CVE-2026-0230 (macOS Cortex XDR Agent can be disabled by a local administrator) and CVE-2026-0231 (Cortex XDR Broker VM information disclosure). For CVE-2026-0230, Palo Alto Networks reported a protection-mechanism issue on macOS that could allow malware to operate without detection if a local admin disables the agent; affected versions include Cortex XDR Agent 8.7-CE prior to 8.7.101-CE and 8.3-CE prior to 8.3.102-CE on macOS, with Palo Alto Networks stating it is not aware of in-the-wild exploitation. For CVE-2026-0231, an authenticated user with network access to the Broker VM could obtain and modify sensitive information by triggering a live terminal session via the Cortex UI and changing configuration settings; the issue affects Cortex XDR Broker VM 30.0.0 prior to 30.0.49, and Palo Alto Networks stated there are no workarounds and that upgrading is required.

Palo Alto Networks also released PAN-SA-2026-0003, incorporating upstream Chromium security fixes into Prisma Browser and listing multiple Chromium CVEs (including CVE-2026-2314, CVE-2026-2321, and CVE-2026-2441); Prisma Browser versions prior to 145.7.9.76 are affected and should be updated. The Canadian Centre for Cyber Security echoed these Palo Alto Networks advisories and urged organizations to apply the necessary updates and mitigations. A separate Canadian advisory covered Splunk product vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and multiple AppDynamics agents, but it is unrelated to the Palo Alto Networks Cortex/Prisma issues.

Share:
Palo Alto Networks Patches Cortex XDR and Prisma Browser Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 8, 20263mo ago

Canadian Centre for Cyber Security issues alert on April 8 Palo Alto advisories

On 2026-04-08, the Canadian Centre for Cyber Security published alert AV26-331 summarizing Palo Alto Networks' April 8 advisories affecting Cortex XDR Agent, Cortex XSOAR Microsoft Teams Marketplace, Cortex XSIAM Microsoft Teams Marketplace, Autonomous Digital Experience Manager, and Prisma Browser. The alert highlighted CVE-2026-0232, CVE-2026-0233, CVE-2026-0234, and the April 2026 Chromium update, and urged organizations to review mitigations and apply updates.

Palo Alto Networks security advisory (AV26-331) - Canadian Centre for Cyber Security

Palo Alto Networks publishes advisory for CVE-2026-0232 in Cortex XDR Agent

On 2026-04-08, Palo Alto Networks published a security advisory for CVE-2026-0232, a vulnerability in Cortex XDR Agent that allows a local administrator to disable the agent on Windows. The advisory represents a new disclosure separate from the March 11 Cortex XDR and Prisma Browser advisories.

CVE-2026-0232 Cortex XDR Agent: Local Administrator can disable the agent on Windows
Mar 12, 20263mo ago

Canadian Centre for Cyber Security issues alert on Palo Alto advisories

On 2026-03-12, the Canadian Centre for Cyber Security published alert AV26-228 summarizing Palo Alto Networks' March 11 advisories and recommending that organizations review the notices, apply mitigations, and update to remediated versions.

Mar 11, 20263mo ago

Palo Alto Networks publishes advisories for Cortex XDR and Prisma Browser flaws

On 2026-03-11, Palo Alto Networks published multiple security advisories covering CVE-2026-0230, a macOS issue allowing a local administrator to disable the Cortex XDR Agent; CVE-2026-0231, a sensitive information disclosure vulnerability in Cortex XDR Broker VM; and PAN-SA-2026-0003, the March 2026 Chromium vulnerability update affecting Prisma Browser. The advisories identified affected version ranges and stated that fixed versions were available.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.