Vulnerability Description
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Prisma Access Agent | < 26.2.1 |
| Apple | Iphone Os | - |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2026-0277Vendor Advisory
FAQ
What is CVE-2026-0277?
CVE-2026-0277 is a vulnerability with a CVSS score of 5.9 (MEDIUM). An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agen...
How severe is CVE-2026-0277?
CVE-2026-0277 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0277?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Prisma Access Agent, Apple Iphone Os.