{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-0277","assignerOrgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","state":"PUBLISHED","assignerShortName":"palo_alto","dateReserved":"2025-11-03T20:44:36.317Z","datePublished":"2026-07-09T19:14:50.806Z","dateUpdated":"2026-07-10T14:19:54.495Z"},"containers":{"cna":{"providerMetadata":{"orgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","shortName":"palo_alto","dateUpdated":"2026-07-09T19:14:50.806Z"},"title":"Prisma Access Agent: Improper Certificate Validation on iOS","datePublic":"2026-07-08T16:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-295","description":"CWE-295 Improper Certificate Validation","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-94","descriptions":[{"lang":"en","value":"CAPEC-94 Adversary in the Middle (AiTM)"}]}],"affected":[{"vendor":"Palo Alto Networks","product":"Prisma Access Agent","versions":[{"status":"affected","version":"0","lessThan":"26.2.1","changes":[{"at":"26.2.1","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected","platforms":["iOS"]},{"vendor":"Palo Alto Networks","product":"Prisma Access Agent","versions":[{"status":"unaffected","version":"All","versionType":"custom"}],"defaultStatus":"unaffected","platforms":["Linux","Windows","macOS","Android","ChromeOS"]}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:iOS:*:*","versionStartIncluding":"25.0","versionEndExcluding":"26.2.1"}]}]}],"descriptions":[{"lang":"en","value":"An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. \n\nThe Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.","supportingMedia":[{"type":"text/html","base64":false,"value":"An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. <br><br>The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected."}]}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0277","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"USER","valueDensity":"DIFFUSE","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.7,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"}}],"configurations":[{"lang":"eng","value":"No special configuration is required to be affected by this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"No special configuration is required to be affected by this issue."}]}],"workarounds":[{"lang":"eng","value":"No known workarounds exist for this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"No known workarounds exist for this issue."}]}],"solutions":[{"lang":"eng","value":"Version\nMinor Version\nSuggested Solution\n\n                                    Prisma Access Agent on iOS\n\n                                    25.0 through 26.2\n                                    Upgrade to 26.2.1 or later.\n                                Prisma Access Agent on Linux\nNo action needed.Prisma Access Agent on Windows\nNo action needed.Prisma Access Agent on macOS\nNo action needed.Prisma Access Agent on Android\nNo action needed.Prisma Access Agent on ChromeOS\nNo action needed.","supportingMedia":[{"type":"text/html","base64":false,"value":"<table><thead><tr><th>Version<br></th><th>Minor Version<br></th><th>Suggested Solution<br></th></tr></thead><tbody><tr>\n                                    <td>Prisma Access Agent on iOS<br></td>\n                                    <td>25.0 through 26.2</td>\n                                    <td>Upgrade to 26.2.1 or later.</td>\n                                </tr><tr><td>Prisma Access Agent on Linux<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on Windows<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on macOS<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on Android<br></td><td></td><td>No action needed.</td></tr><tr><td>Prisma Access Agent on ChromeOS<br></td><td></td><td>No action needed.</td></tr></tbody></table>"}]}],"exploits":[{"lang":"eng","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}]}],"timeline":[{"time":"2026-07-08T16:00:00.000Z","lang":"en","value":"Initial Publication"}],"credits":[{"lang":"en","value":"our internal security research teams","type":"finder"}],"source":{"discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-10T14:19:46.628829Z","id":"CVE-2026-0277","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-10T14:19:54.495Z"}}]}}