CVE-2026-0232 Details
Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
A vulnerability in the Palo Alto Networks Cortex XDR agent for Windows allows local administrators to disable the agent. This flaw could be exploited by malware to carry out malicious activities without being detected. The issue arises in versions 9.0.0 prior to 9.0.1, 8.9.0 prior to 8.9.1, and 8.7.101-CE prior to 8.7.101-CE, all without Content Update 2120.
To address this vulnerability, users should update their Cortex XDR agent to version 9.0.1 or later, 8.9.1 or later, or 8.7.101-CE. For versions 8.3-CE and 7.9-CE, applying Content Update 2120 is sufficient.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0232 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-15 | External Control of System or Configuration Setting | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks cortex xdr agent | >= 8.7.0, < 8.7.101 7.9 8.3 8.9.0 - 9.0.0 - |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | New CVE Received | [email protected] |