CVE-2026-0248

An improper certificate validation vulnerability in the Prisma Access AgentĀ® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.
CVSS

No CVSS.

Configurations

No configuration.

History

13 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 19:16

Updated : 2026-05-14 16:21


NVD link : CVE-2026-0248

Mitre link : CVE-2026-0248

CVE.ORG link : CVE-2026-0248


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation