Description
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic.

The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
Published: 2026-07-09
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper certificate validation flaw in the Prisma Access Agent for iOS allows an attacker to perform a man‑in‑the‑middle attack that intercepts VPN traffic. Because the client accepts certificates that should not be trusted, confidentiality of the data transmitted over the VPN can be compromised. This is a CWE‑295 weakness involving improper certificate validation. The CVSS score is 5.7, indicating a moderate level of severity. The EPSS score is <1%, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to either local network access or the ability to masquerade as a certificate authority. While the exploit is feasible, the low EPSS score and moderate CVSS indicate that the attack risk is not extreme, but the impact to confidentiality remains significant.

Affected Systems

The vulnerability affects only the iOS version of the Prisma Access Agent from Palo Alto Networks. Specifically, any installation of version 25.0 through 26.2 on iOS devices is impacted. Other operating systems—Windows, macOS, Linux, Android, and ChromeOS—are not affected.

Risk and Exploitability

The CVSS score of 5.7 reflects moderate severity, largely due to the impact on confidentiality and limited privilege escalation. The EPSS score of <1% indicates a low probability of current exploitation. The vulnerability is not included in CISA’s KEV catalog, suggesting no known widespread attacks. Attacking this flaw requires an iOS device running an affected Prisma Access Agent version (25.0 through 26.2) and the capability to supply a forged certificate, typically achievable via a compromised network environment or malicious certificate authority.

Generated by OpenCVE AI on July 29, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Prisma Access Agent on iOS to version 26.2.1 or, ensure that the most recent iOS system update is applied to maintain OS‑level certificate validation safeguards.
  • Deploy network monitoring tools to detect anomalous certificate exchanges or potential MitM activity on VPN traffic.
  • Ensure VPN settings use certificate pinning to mitigate MitM risk.

Generated by OpenCVE AI on July 29, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
Title Prisma Access Agent: Improper Certificate Validation on iOS
First Time appeared Palo Alto Networks
Palo Alto Networks prisma Access Agent
Weaknesses CWE-295
CPEs cpe:2.3:a:palo_alto_networks:prisma_access_agent:*:*:*:*:*:iOS:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks prisma Access Agent
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Prisma Access Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-07-10T14:19:54.495Z

Reserved: 2025-11-03T20:44:36.317Z

Link: CVE-2026-0277

cve-icon Vulnrichment

Updated: 2026-07-10T14:19:49.401Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-295

    Improper Certificate Validation