Palo Alto Networks Patches Cortex XDR and Prisma Browser Vulnerabilities
Palo Alto Networks published security advisories addressing multiple vulnerabilities affecting Cortex XDR components and Prisma Browser, including CVE-2026-0230 (macOS Cortex XDR Agent can be disabled by a local administrator) and CVE-2026-0231 (Cortex XDR Broker VM information disclosure). For CVE-2026-0230, Palo Alto Networks reported a protection-mechanism issue on macOS that could allow malware to operate without detection if a local admin disables the agent; affected versions include Cortex XDR Agent 8.7-CE prior to 8.7.101-CE and 8.3-CE prior to 8.3.102-CE on macOS, with Palo Alto Networks stating it is not aware of in-the-wild exploitation. For CVE-2026-0231, an authenticated user with network access to the Broker VM could obtain and modify sensitive information by triggering a live terminal session via the Cortex UI and changing configuration settings; the issue affects Cortex XDR Broker VM 30.0.0 prior to 30.0.49, and Palo Alto Networks stated there are no workarounds and that upgrading is required.
Palo Alto Networks also released PAN-SA-2026-0003, incorporating upstream Chromium security fixes into Prisma Browser and listing multiple Chromium CVEs (including CVE-2026-2314, CVE-2026-2321, and CVE-2026-2441); Prisma Browser versions prior to 145.7.9.76 are affected and should be updated. The Canadian Centre for Cyber Security echoed these Palo Alto Networks advisories and urged organizations to apply the necessary updates and mitigations. A separate Canadian advisory covered Splunk product vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and multiple AppDynamics agents, but it is unrelated to the Palo Alto Networks Cortex/Prisma issues.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Canadian Centre for Cyber Security issues alert on April 8 Palo Alto advisories
On 2026-04-08, the Canadian Centre for Cyber Security published alert AV26-331 summarizing Palo Alto Networks' April 8 advisories affecting Cortex XDR Agent, Cortex XSOAR Microsoft Teams Marketplace, Cortex XSIAM Microsoft Teams Marketplace, Autonomous Digital Experience Manager, and Prisma Browser. The alert highlighted CVE-2026-0232, CVE-2026-0233, CVE-2026-0234, and the April 2026 Chromium update, and urged organizations to review mitigations and apply updates.
Palo Alto Networks publishes advisory for CVE-2026-0232 in Cortex XDR Agent
On 2026-04-08, Palo Alto Networks published a security advisory for CVE-2026-0232, a vulnerability in Cortex XDR Agent that allows a local administrator to disable the agent on Windows. The advisory represents a new disclosure separate from the March 11 Cortex XDR and Prisma Browser advisories.
Canadian Centre for Cyber Security issues alert on Palo Alto advisories
On 2026-03-12, the Canadian Centre for Cyber Security published alert AV26-228 summarizing Palo Alto Networks' March 11 advisories and recommending that organizations review the notices, apply mitigations, and update to remediated versions.
Palo Alto Networks publishes advisories for Cortex XDR and Prisma Browser flaws
On 2026-03-11, Palo Alto Networks published multiple security advisories covering CVE-2026-0230, a macOS issue allowing a local administrator to disable the Cortex XDR Agent; CVE-2026-0231, a sensitive information disclosure vulnerability in Cortex XDR Broker VM; and PAN-SA-2026-0003, the March 2026 Chromium vulnerability update affecting Prisma Browser. The advisories identified affected version ranges and stated that fixed versions were available.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
6 references tracked. Mallory keeps watching after this page renders.
Palo Alto Networks security advisory (AV26-331) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceCVE-2026-0232 Cortex XDR Agent: Local Administrator can disable the agent on Windows
security.paloaltonetworks.com
Open sourcePalo Alto Networks security advisory (AV26-228) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceCVE-2026-0230 Cortex XDR Agent: Local Administrator can disable the agent on macOS
security.paloaltonetworks.com
Open sourcePAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026)
security.paloaltonetworks.com
Open sourceCVE-2026-0231 Cortex XDR Broker VM: Sensitive Information Disclosure Vulnerability
security.paloaltonetworks.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


