CVE-2026-0244 Details
Description
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.
A vulnerability allowing improper certificate validation has been identified in Palo Alto Networks Prisma SD-WAN ION. This issue enables a man-in-the-middle (MitM) attacker to impersonate the controller. The vulnerability exists in versions 6.5.1 prior to 6.5.3-b15, 6.4.1 prior to 6.4.3-b8, and 6.3.1 prior to 6.3.6-b10.
Users can upgrade to Prisma SD-WAN ION 6.5.3-b15 or later, 6.4.3-b8 or later, or 6.3.6-b10 or later. For those using versions 6.1 or 5.6, no action is needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0244 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks prisma sd-wan | >= 6.3.1, < 6.3.6 >= 6.4.1, < 6.4.3 >= 6.5.1, < 6.5.3 6.3.6 - 6.3.6 b6 6.3.6 b9 6.4.3 - 6.4.3 b6 6.4.3 b8 6.5.3 - 6.5.3 b11 6.5.3 b9 6.5.3 i-b10 |
CPE
Remediation
| |
| paloaltonetworks ion 1200 | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-c-na | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-c-row | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-c5g-ww | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-s | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-s-c-na | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-s-c-row | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 1200-s-c5g-ww | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 3102v | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 3104v | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 3108v | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 3200 | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 3200h | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 3200h-c5g-ww | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 5200 | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 7108v | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 7116v | All versions |
CPE
Remediation
| |
| paloaltonetworks ion 9200 | All versions |
CPE
Remediation
| |
| paloaltonetworks pa-5440 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |