Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0301

CVE-2026-0301 release notes and known issues

PAN-OS: Information Disclosure Vulnerability in URL Filtering

Scope: Cloud NGFW. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Cloud NGFW
  • PAN-OS
  • Prisma Access

Affected versions

  • All on AWS*, All on Azure*
  • None
  • < 11.1.16-h1
  • < 10.2.8
  • < 10.2.10

Fixed versions or updates

  • None on AWS*, None on Azure*
  • All
  • >= 11.1.16-h1
  • >= 10.2.8
  • >= 10.2.10

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW* Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.1 12.1.2 through 12.1.6-h* No action needed. PAN-OS 11.2 11.2.0 through 11.2.12 No action needed. PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or later. PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.16-h1 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 12.1 12.1.2 through 12.1.* No action needed. Prisma Access 11.2 11.2.0 through 11.2* No action needed. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

PAN-OS: Information Disclosure Vulnerability in URL Filtering

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source