CVE-2026-0232
Received
Received - Intake
Bypass Protection Vulnerability in Palo Alto Cortex XDR Agent
Publication date: 2026-04-13
Last updated on: 2026-04-13
Assigner: Palo Alto Networks, Inc.
Description
Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent.Β This issue may be leveraged by malware to perform malicious activity without detection.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| palo_alto_networks | cortex_xdr_agent | * |
| palo_alto_networks | cortex_xdr_agent | to 9.0.1 (exc) |
| palo_alto_networks | cortex_xdr_agent | to 8.9.1 (exc) |
| palo_alto_networks | cortex_xdr_agent | to 8.7.101-CE (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-15 | One or more system settings or configuration elements can be externally controlled by a user. |