Palo Alto Networks on Wednesday published seven security advisories, describing corresponding vulnerabilities in its products, as well as the implementation of recent Chrome security patches
See also: Palo Alto Networks: Brute-force attempts against PAN-OS GlobalProtect gateways

The most serious of the vulnerabilities patched is CVE-2025-4232, a high-severity vulnerability related to improper wildcard spoofing in GlobalProtect for macOS, which could lead to malicious code injection. The issue affects the application's log collection functionality and can be exploited by authenticated users to escalate privileges to root, Palo Alto Networks warns.
Palo Alto also noted the implementation of 11 Chrome security fixes in its products, as well as a patch for the CVE-2025-4233, which concerns an improper implementation in the cache function of the Prisma Access Browser. In addition, an update was released for a medium severity vulnerability (CVE-2025-4231) that concerns command injection in PAN-OS, allowing an attacker with administrator credentials to perform actions with root privileges.
Another command-line vulnerability in PAN-OS, with the identifier CVE-2025-4230, allows an attacker logged in to an administrator account with CLI access to bypass system restrictions and execute arbitrary commands with root privileges.
See also: Nearly 24,000 IPs behind Palo Alto GlobalProtect scans
The company also fixed a bug in PAN-OS that could allow users who are able to intercept packets sent by the firewall to see unencrypted data traveling through the SD-WAN, as well as an incorrect privilege assignment issue in the Cortex XDR Broker VM, which could allow malicious users to escalate privileges to root.

Additionally, the company addressed an improper access control vulnerability in GlobalProtect 's Endpoint Traffic Policy Enforcement feature for Windows and macOS, which resulted in packets being sent without encryption. This could allow an attacker with physical access to the network to insert a malicious device and intercept traffic.
Palo Alto Networks says it is not aware of any of these vulnerabilities being exploited in attacks. More information is available on the company's security advisory page
See also: Palo Alto Networks flags new firewall flaw as exploitable
Based on the above information, it appears that Palo Alto Networks has issued an extensive series of security patches covering critical and medium severity vulnerabilities in various of its products, such as PAN-OS, GlobalProtect, and Cortex XDR. This demonstrates the importance of continuous monitoring and maintenance of security systems, especially in environments that rely on firewalls, VPNs, and endpoint monitoring systems.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
