CVE-2026-0232

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.9:*:*:*:critical_environment:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.3:*:*:*:critical_environment:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.9.0:-:*:*:-:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:9.0.0:-:*:*:-:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

07 Jul 2026, 18:19

Type Values Removed Values Added
First Time Paloaltonetworks
Microsoft windows
Paloaltonetworks cortex Xdr Agent
Microsoft
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4
CWE NVD-CWE-noinfo
References () https://security.paloaltonetworks.com/CVE-2026-0232 - () https://security.paloaltonetworks.com/CVE-2026-0232 - Vendor Advisory
CPE cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.3:*:*:*:critical_environment:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.9:*:*:*:critical_environment:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.9.0:-:*:*:-:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:9.0.0:-:*:*:-:*:*:*

13 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 08:16

Updated : 2026-07-07 18:19


NVD link : CVE-2026-0232

Mitre link : CVE-2026-0232

CVE.ORG link : CVE-2026-0232


JSON object : View

Products Affected

paloaltonetworks

  • cortex_xdr_agent

microsoft

  • windows
CWE
CWE-15

External Control of System or Configuration Setting

NVD-CWE-noinfo