Palo Alto Networks Vulnerabilities and Affected Products
Vulnerabilities associated with Cortex XDR Broker VM.
Products
Clear product- PAN-OS189 vulnerabilities
- Prisma Access112 vulnerabilities
- Cloud NGFW104 vulnerabilities
- GlobalProtect App38 vulnerabilities
- Cortex XDR Agent24 vulnerabilities
- Expedition12 vulnerabilities
- Prisma Access Agent12 vulnerabilities
- Cortex XSOAR11 vulnerabilities
- GlobalProtect UWP App9 vulnerabilities
- Prisma Browser9 vulnerabilities
- Cortex XDR Broker VM8 vulnerabilities
- Panorama7 vulnerabilities
- Prisma Cloud Compute4 vulnerabilities
- Global Protect Agent3 vulnerabilities
- Trust Protection Foundation3 vulnerabilities
- Autonomous Digital Experience Manager2 vulnerabilities
- Bridgecrew Checkov2 vulnerabilities
- Checkov by Prisma Cloud2 vulnerabilities
- Palo Alto Networks Expedition2 vulnerabilities
- Palo Alto Networks PAN-OS2 vulnerabilities
- Prisma Access Browser2 vulnerabilities
- Prisma SD-WAN ION2 vulnerabilities
- Traps2 vulnerabilities
- ActiveMQ Content Pack1 vulnerability
- Broker VM1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Cortex XDR Broker VM: Privilege Escalation (PE) VulnerabilityA privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. CWE-269Jul 9, 2026 | CVSS1.1v4.0 | EPSS0.098% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-0231MEDIUM | Cortex XDR Broker VM: Sensitive Information Disclosure VulnerabilityAn information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting. The attacker must have network access to the Broker VM to exploit this issue. CWE-497Mar 11, 2026 | CVSS5.7v4.0 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2184MEDIUM | Cortex XDR Broker VM: Secrets Shared Across Multiple Broker VM ImagesA credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the Broker VM to exploit this issue. CWE-1392Aug 13, 2025 | CVSS5.3v4.0 | EPSS0.174% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4228MEDIUM | Cortex XDR Broker VM: Privilege Escalation (PE) VulnerabilityAn incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root. CWE-266Jun 12, 2025 | CVSS4.6v4.0 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0134MEDIUM | Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VMA code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM. CWE-94May 14, 2025 | CVSS6.5v4.0 | EPSS0.449% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0132MEDIUM | Cortex XDR Broker VM: Unauthenticated User Can Disable Internal ServicesA missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue. CWE-306May 14, 2025 | CVSS6.9v4.0 | EPSS0.427% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0119MEDIUM | Cortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VMA command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM. CWE-78Apr 11, 2025 | CVSS6.3v4.0 | EPSS0.515% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0113MEDIUM | Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker ContainersA problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server. CWE-424Feb 12, 2025 | CVSS5.3v4.0 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |