CVE-2026-0277

Prisma Access Agent: Improper Certificate Validation on iOS

Severity
Medium 5.7
CVSS 4.0
Exploited
Not listed
EPSS
0.001
1.5th percentile
Discovered by
Vendor
Published by the vendor
Published
Jul 9, 2026
Assigned by palo_alto

Description

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · Prisma Access Agent
  • Palo Alto Networks · Prisma Access Agent

Credit

our internal security research teams

Vendor remediation

Version Minor Version Suggested Solution Prisma Access Agent on iOS 25.0 through 26.2 Upgrade to 26.2.1 or later. Prisma Access Agent on Linux No action needed.Prisma Access Agent on Windows No action needed.Prisma Access Agent on macOS No action needed.Prisma Access Agent on Android No action needed.Prisma Access Agent on ChromeOS No action needed.