Palo Alto Networks patches Cortex XSOAR and XSIAM flaw CVE-2026-0274 that can expose restricted resources

Palo Alto Networks released fixes for a serious vulnerability in Cortex XSOAR and Cortex XSIAM that could let attackers access and change protected resources. The flaw, CVE-2026-0274, is a high-severity improper credential-validation issue in the CommvaultSecurityIQ integration and does not require special configuration to be triggered; Palo Alto also patched eight additional medium- and low-severity bugs in PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App.
Why it matters: Teams using affected Palo Alto platforms should install updates because the flaw could undermine access controls in tools used for security operations and response. Even without known active exploitation, these are widely deployed enterprise products and should be patched before attackers can weaponize the bugs.

Sources

Splunk, Palo Alto Networks Patch Severe Vulnerabilities
Ionut Arghire 2026.06.11 100% relevant
This article establishes a separate Palo Alto patch event around CVE-2026-0274 in Cortex XSOAR and Cortex XSIAM rather than updating an existing tracked story.
← Back to all stories