<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Panorama - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/panorama/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 08 Jul 2026 16:10:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/panorama/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-07-pan-os-xss/</link><pubDate>Wed, 08 Jul 2026 16:10:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-pan-os-xss/</guid><description>Palo Alto Networks has disclosed multiple low-severity cross-site scripting (XSS) vulnerabilities, CVE-2026-0279, in PAN-OS software affecting the User-ID Authentication Portal, GlobalProtect gateway/portal features, and Clientless VPN, which could allow a malicious unauthenticated user to inject and execute JavaScript in a victim's browser.</description><content:encoded><![CDATA[<p>Palo Alto Networks has released an advisory concerning CVE-2026-0279, which identifies multiple low-severity cross-site scripting (XSS) vulnerabilities across various components of its PAN-OS software. These vulnerabilities specifically affect the User-ID™ Authentication Portal (also known as Captive Portal), GlobalProtect™ gateway/portal features, and Clientless VPN. An unauthenticated attacker could exploit these flaws to inject and store malicious JavaScript payloads, which would then execute in the context of a legitimate user's browser when they access the vulnerable component. The risk associated with this issue is significantly reduced by adhering to Palo Alto Networks' recommended best practices, which include restricting access to management interfaces and the User-ID Authentication Portal to only trusted internal IP addresses. Cloud NGFW products are not affected. Affected versions include PAN-OS 12.1 prior to 12.1.8, 11.2 prior to 11.2.13, 11.1 prior to 11.1.16, and all 10.2 versions, along with specific Prisma Access versions. No active exploitation has been reported.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Vulnerability Identification</strong>: An unauthenticated attacker identifies a vulnerable input field or parameter within the User-ID Authentication Portal, GlobalProtect gateway/portal, or Clientless VPN of an exposed PAN-OS device.</li>
<li><strong>Payload Crafting</strong>: The attacker constructs a malicious JavaScript payload designed to achieve an objective such as session hijacking, credential theft, or redirection to a malicious website.</li>
<li><strong>Payload Injection</strong>: The crafted JavaScript payload is injected by the attacker into the identified vulnerable component through an unauthenticated network request.</li>
<li><strong>Persistent Storage</strong>: The PAN-OS application processes and stores the malicious payload, embedding it within the user-facing content of the vulnerable component.</li>
<li><strong>Victim Interaction</strong>: A legitimate user accesses the compromised PAN-OS component (e.g., logs into the User-ID Authentication Portal or uses a GlobalProtect feature).</li>
<li><strong>Client-Side Execution</strong>: The injected malicious JavaScript is rendered and executed by the victim's web browser as part of the legitimate PAN-OS application interface.</li>
<li><strong>Malicious Action</strong>: The executed JavaScript performs its intended action, potentially leading to unauthorized access to the victim's session, exposure of sensitive information, or further client-side attacks.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerabilities, categorized as low severity, primarily impact the confidentiality and integrity of users interacting with the affected PAN-OS portals and features. While no active exploitation has been reported, successful exploitation could lead to client-side attacks where an attacker executes malicious JavaScript within a victim's browser. This could result in session hijacking, allowing unauthorized access to the victim's user session, or credential theft if the script is designed to capture login information. The overall product confidentiality and integrity are rated as LOW, and availability is rated as NONE, indicating that the vulnerability does not directly compromise the firewall's core functions or lead to denial of service. The impact is minimized when the management interfaces and portal access are restricted to trusted internal networks, as per best practices.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-0279 immediately by upgrading all affected PAN-OS devices and Prisma Access deployments to the specified fixed versions: PAN-OS 12.1.8 or later, PAN-OS 11.2.13 or later, PAN-OS 11.1.16 or later, or a supported fixed version for PAN-OS 10.2. Prisma Access 11.2 should be upgraded to 11.2.7-h18 or later, and Prisma Access 10.2 to 10.2.10-h39 or later.</li>
<li>Implement network access restrictions to the management interface and User-ID Authentication Portal according to Palo Alto Networks' best practice deployment guidelines, ensuring access is limited to only trusted internal IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">threat</category><category>xss</category><category>vulnerability</category><category>firewall</category><category>network-device</category><category>web-application</category></item><item><title>CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface</title><link>https://feed.craftedsignal.io/briefs/2026-07-pan-os-cve-2026-0281/</link><pubDate>Wed, 08 Jul 2026 16:08:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-pan-os-cve-2026-0281/</guid><description>An information disclosure vulnerability (CVE-2026-0281) in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to obtain web session tokens via user interaction with a malicious link, potentially leading to unauthorized access to the management interface.</description><content:encoded><![CDATA[<p>Palo Alto Networks has disclosed CVE-2026-0281, an information disclosure vulnerability affecting the management web interface of PAN-OS software across PA-Series, VM-Series firewalls, and Panorama devices. This vulnerability allows an unauthenticated attacker with network access to the management interface to obtain web session tokens. Exploitation requires a legitimate user to first click on a malicious link provided by the attacker, making it a client-side vulnerability with user interaction. While the vulnerability has been internally discovered, Palo Alto Networks is not aware of any malicious exploitation in the wild. This issue impacts PAN-OS versions 12.1.2 through 12.1.7-h*, 11.2.0 through 11.2.12, 11.1.0 through 11.1.15-h*, and all 10.2.x versions. The risk is minimized by following best practices of restricting management interface access to trusted internal IP addresses.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Attacker crafts malicious link</strong>: An unauthenticated attacker creates a specially crafted malicious URL designed to exploit CVE-2026-0281 on the target PAN-OS management interface.</li>
<li><strong>Attacker delivers malicious link</strong>: The attacker sends the malicious link to a legitimate user who has administrative access to the vulnerable PAN-OS management interface, likely via a social engineering campaign such as a spearphishing email or instant message.</li>
<li><strong>Legitimate user clicks link</strong>: The targeted legitimate user, believing the link to be benign, clicks on the malicious URL while their browser is authenticated to the PAN-OS management interface.</li>
<li><strong>Browser requests PAN-OS interface</strong>: The user's browser makes a request to the PAN-OS management web interface, triggering the information disclosure vulnerability as a result of the malicious link's parameters or redirection.</li>
<li><strong>PAN-OS discloses session token</strong>: The vulnerable PAN-OS management web interface processes the request and, due to CVE-2026-0281, inadvertently discloses the user's active web session token to the attacker's controlled infrastructure.</li>
<li><strong>Attacker captures session token</strong>: The attacker's controlled server or client-side script captures the exfiltrated web session token.</li>
<li><strong>Attacker authenticates to PAN-OS</strong>: The attacker uses the stolen web session token to establish an unauthorized, authenticated session with the PAN-OS management interface, bypassing the need for credentials.</li>
<li><strong>Unauthorized management access</strong>: With the compromised session, the attacker gains the ability to perform administrative actions on the firewall, such as modifying configurations, exfiltrating data, or establishing persistence within the network.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The primary impact of successful exploitation of CVE-2026-0281 is the unauthorized disclosure of web session tokens, which could lead to complete compromise of the Palo Alto Networks firewall management interface. Although Palo Alto Networks is not aware of any in-the-wild exploitation, organizations that fail to patch or implement proper network segmentation for their management interfaces could face severe consequences. An attacker gaining unauthorized access could reconfigure firewall rules, disable security features, establish backdoor access, or use the firewall as a pivot point for further attacks into internal networks, leading to data breaches or service disruptions. The extent of impact depends heavily on the access controls protecting the management interface.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li><strong>Patch CVE-2026-0281</strong>: Immediately upgrade affected PAN-OS software versions to the remediated versions as per Palo Alto Networks' advisory for CVE-2026-0281.</li>
<li><strong>Restrict management interface access</strong>: Secure access to your Palo Alto Networks firewall management interfaces by restricting access to only trusted internal IP addresses, as recommended by Palo Alto Networks' best practice deployment guidelines.</li>
<li><strong>Review network segmentation</strong>: Ensure robust network segmentation for management networks to prevent unauthenticated external access to firewall management interfaces.</li>
<li><strong>Educate users on phishing</strong>: Reinforce user education regarding spearphishing attempts and malicious links, as user interaction is required for this vulnerability's exploitation.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">threat</category><category>information-disclosure</category><category>network-device</category><category>firewall</category><category>palo-alto-networks</category><category>cve</category></item><item><title>CVE-2026-0282 PAN-OS: Unauthenticated File Deletion Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-07-cve-2026-0282-pan-os-file-deletion/</link><pubDate>Wed, 08 Jul 2026 16:06:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-cve-2026-0282-pan-os-file-deletion/</guid><description>An unauthenticated attacker with network access to the management web interface of Palo Alto Networks PAN-OS software can exploit CVE-2026-0282, a file deletion vulnerability, to delete files from a temporary directory, impacting PA-Series and VM-Series firewalls, and Panorama appliances.</description><content:encoded><![CDATA[<p>Palo Alto Networks has disclosed CVE-2026-0282, a low-severity file deletion vulnerability impacting its PAN-OS software, which runs on PA-Series and VM-Series firewalls, as well as Panorama management appliances (virtual and M-Series). An unauthenticated attacker with network access to the management web interface can exploit this flaw to delete files from a temporary directory. The vulnerability was discovered internally and has no reported instances of in-the-wild exploitation. While the CVSS score is low (2.7-5.1 depending on configuration), organizations are urged to patch to prevent potential misuse, especially if management interfaces are exposed to untrusted networks. Cloud NGFW and Prisma Access products are not affected by this issue, simplifying the scope of necessary updates.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An unauthenticated attacker establishes network connectivity to the management web interface of a vulnerable PAN-OS device.</li>
<li>The attacker sends a specially crafted request to the web interface.</li>
<li>The PAN-OS software processes the request, which due to improper input validation, results in arbitrary file deletion.</li>
<li>The system deletes a file from a temporary directory on the vulnerable device.</li>
<li>No immediate integrity or availability impact on the product itself is observed beyond temporary file deletion.</li>
<li>The objective is the deletion of temporary files, which could potentially disrupt operations or be a precursor to other attacks.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The primary impact of CVE-2026-0282 is the ability for an unauthenticated attacker to delete files within a temporary directory on affected PAN-OS devices. While the direct consequence of deleting temporary files is often minimal, such actions could potentially disrupt operations or serve as a precursor to more sophisticated attacks if combined with other vulnerabilities. Palo Alto Networks stresses that the security risk is substantially mitigated by adhering to best practice deployment guidelines, which involve restricting management interface access to only trusted internal IP addresses. There are no known instances of malicious exploitation in the wild.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade affected PAN-OS instances to fixed versions (12.1.8, 11.2.13, 11.1.16, or later, as per CVE-2026-0282 advisory) to remediate the vulnerability.</li>
<li>Implement network access controls to restrict access to the management web interface of PA-Series, VM-Series, and Panorama devices from untrusted networks, as recommended in the CVE-2026-0282 advisory.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">threat</category><category>vulnerability</category><category>pan-os</category><category>network-device</category><category>file-deletion</category></item></channel></rss>