Palo Alto Networks has released its August 12, 2026 security bulletin, disclosing 11 new vulnerabilities affecting PAN-OS, the GlobalProtect App, Prisma Access Agent, and Prisma Browser, along with a monthly Chromium update rollup.
The patch batch spans information disclosure, local privilege escalation, buffer overflow, certificate validation bypass, and anti-tamper bypass flaws.
Severity scores range from a low 1.1 to a moderate 7.2 on the CVSS scale, meaning none of the newly published issues reach critical severity in this release cycle.
Security teams monitoring PAN-OS vulnerabilities should evaluate endpoint exposures across enterprise environments.
The most notable infrastructure entry, CVE-2026-0301, is a low-severity (CVSS 1.7) information disclosure vulnerability in PAN-OS URL Filtering. It impacts Cloud NGFW and multiple PAN-OS release branches, including 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access deployments hosted on AWS and Azure.
Fixes are available across the affected PAN-OS 11.1 and 10.2 releases, and Cloud NGFW and public-cloud Prisma Access instances have already been remediated by Palo Alto Networks.
As detailed in the official Palo Alto Networks Security Advisories, organizations should review specific release tables to ensure all firewall management interfaces are updated.
The GlobalProtect App received the highest concentration of fixes this month, with six distinct CVEs disclosed:
Patches for several GlobalProtect app flaws on the 6.0 branch carry an estimated availability date of August 31, 2026, indicating remediation efforts remain ongoing for legacy clients.
| CVE Identifier | Component / Product | CVSS Score | Vulnerability Type & Scope | Patch Status / ETA |
| CVE-2026-0301 | PAN-OS URL Filtering / Prisma Access | 1.7 | Information Disclosure | Patched / Cloud Remediated |
| CVE-2026-0299 | GlobalProtect App (Desktop) | 5.9 | Local Privilege Escalation | Patched (Branch 6.0 ETA Aug 31) |
| CVE-2026-0298 | GlobalProtect Windows PLAP | 5.2 | Local Code Execution | Patched |
| CVE-2026-0297 | GlobalProtect App (Mobile/Desktop) | 5.2 | UDP Handshake Buffer Overflow | Fixed in 6.3.5+ |
| CVE-2026-0294 | Prisma Access Agent (Win/macOS) | 6.0 | Local Privilege Escalation | Pending (ETA Aug 20, 2026) |
| CVE-2026-0293 | Prisma Access Agent (Windows) | 5.6 | Anti-Tamper Protection Bypass | Pending (ETA Aug 20, 2026) |
| PAN-SA-2026-0011 | Prisma Browser (< 148.18.4.217) | 7.2 | Chromium Rollup Vulnerabilities | Fixed in 150.49.8.187+ |
Prisma Access Agent was subject to four separate security disclosures:
Separately, Palo Alto Networks issued advisory PAN-SA-2026-0011, addressing Chromium vulnerabilities in Prisma Browser builds prior to 148.18.4.217. With a CVSS score of 7.2, this is the highest risk score in the August update cycle.
Organizations using Prisma Browser should prioritize updating to version 150.49.8.187 or later.
While none of the flaws disclosed in this cycle are currently flagged as actively exploited, the volume of GlobalProtect and Prisma Access Agent fixes underscores endpoint exposure.
Administrators should prioritize updating internet-facing PAN-OS management interfaces and URL filtering policies, followed by desktop VPN clients on Windows and macOS, where privilege escalation vulnerabilities intersect.