cbcvebase.
CVE-2026-0301
published 2026-08-13

CVE-2026-0301: An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access…

PriorityP417low1.7CVSS 4.0
AVNACLATPPRNUINVCLVINVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
EPSS
0.31%
24.2th percentile
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

Affected

8 ranges
VendorProductVersion rangeFixed in
palo_alto_networkscloud_ngfw
palo_alto_networkspan-os>= 10.2.0 < 10.2.810.2.8
palo_alto_networkspan-os>= 11.1.0 < 11.1.16-h111.1.16-h1
palo_alto_networksprisma_access>= 10.2.0 < 10.2.1010.2.10
paloaltocloud_ngfw
paloaltopan-os
paloaltoprisma_access
vaporleaf-kit>= 0 < 1.4.11.4.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.