CVE-2026-0244

HIGH

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

Affects 0 products across 3 vendors.

BCS3.01
CVSS 3.18.1
CVSS v45.2
EPSS0.2%
Percentile12th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-295: CWE-295
Related Attack Patterns (CAPEC)
CAPEC-459 Creating a Rogue Certification Authority Certificate
via CWE-295
CAPEC-475 Signature Spoofing by Improper Validation
via CWE-295

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A low severity vulnerability affects Palo Alto systems (CVE-2026-0244). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-059138-I • Model: rule-based-v1 • Confidence: LOW

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0244?
A low severity vulnerability affects Palo Alto systems (CVE-2026-0244). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-0244?
CVE-2026-0244 has CVSS 8.1 (High). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.2%.
Is CVE-2026-0244 actively exploited?
No confirmed active exploitation of CVE-2026-0244 as of 2026-07-15.
How do I remediate CVE-2026-0244?
Priority: MONITOR. PSIRT: [email protected]
What systems are affected by CVE-2026-0244?
CVE-2026-0244 affects: Palo Alto, Palo Alto Networks, Prisma.
Vulnerability Details
CVE IDCVE-2026-0244
BSIDBS-2026-GLOBAL-059138-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-13
Last Modified2026-07-14
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller. CVSS vector: Not available.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Palo Alto —
Palo Alto Networks —
Prisma —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 73 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceLOW
Enriched At2026-05-24
SHA-512 Audit Hash9899e178c1ee5ec9f65e6a4632529b9e26378d9c8ff2c02de64ebbd77b3b148034ae02b40158a3a6baa74e14a3000beaa344f9ef361cbb4091c80c7157a4e2e9
Related CVEs affecting Palo Alto
CVE-2026-0300 9.8 Siemens RUGGEDCOM APE1808 Devices CVE-2026-0263 9.8 A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks... CVE-2026-0257 9.1 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway... CVE-2026-0259 8.8 An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFir... CVE-2026-0240 8.7 An information disclosure vulnerability in Trust Protection Foundation enable...
View all Palo Alto CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →