Known vulnerabilities in Cortex XDR Agent for Windows

Software CPE: cpe:2.3:a:palo_alto_networks:cortex_xdr_agent:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cortex XDR Agent for Windows Cortex XDR Agent for Windows is affected by 23 known vulnerabilities: 1 medium, 22 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125524 - External Control of System or Configuration Setting
CVE-2026-0232
CWE-15 Low
No
No
8.7.101-CE, 8.9.1, 9.0.1, 9.1.0 09.04.2026 SB2026040906
#VU107392 - NULL Pointer Dereference
CVE-2025-0121
CWE-476 Low
No
No
7.9.103-CE HF, 8.3.101-CE HF, 8.5.2, 8.6.1 11.04.2025 SB2025041130
#VU104023 - Improper Check for Unusual or Exceptional Conditions
CVE-2025-0112
CWE-754 Low
No
No
8.3.101-CE, 8.5.1 18.02.2025 SB2025021805
#VU98346 - Improper Check for Unusual or Exceptional Conditions
CVE-2024-9469
CWE-754 Low
No
No
7.9.102-CE, 8.3.1, 8.4.1 10.10.2024 SB2024101019
#VU97291 - Expected Behavior Violation
CVE-2024-8690
CWE-440 Low
No
No
8.2 16.09.2024 SB2024091608
#VU94365 - Improper Verification of Cryptographic Signature
CVE-2024-5912
CWE-347 Low
No
No
7.9.102-CE, 8.2.2 16.07.2024 SB2024071622
#VU94362 - Origin Validation Error
CVE-2024-5905
CWE-346 Low
No
No
7.9.102-CE, 8.1.2, 8.2.1 16.07.2024 SB2024071623
#VU94360 - Improper Privilege Management
CVE-2024-5907
CWE-269 Low
No
No
7.9.102-CE, 8.2.3, 8.3.1 16.07.2024 SB2024071621
#VU94359 - Improper Privilege Management
CVE-2024-5909
CWE-269 Low
Available
No
7.9.102-CE, 8.1.2, 8.2.1 16.07.2024 SB2024071623
#VU80763 - Improper Handling of Exceptional Conditions
CVE-2023-3280
CWE-755 Low
Available
No
7.9.3, 7.9.101-CE, 8.0.2 13.09.2023 SB2023091368
#VU72069 - Security Features
CVE-2023-0002
CWE-254 Low
No
No
5.0.12.22203, 7.5.101-CE 08.02.2023 SB2023020867
#VU72068 - Cleartext Storage of Sensitive Information
CVE-2023-0001
CWE-312 Low
No
No
7.5.101-CE 08.02.2023 SB2023020867
#VU67351 - Improper Link Resolution Before File Access ('Link Following')
CVE-2022-0029
CWE-59 Low
No
No
5.0.12-hotfix, 7.5.101-CE, 7.7.3 14.09.2022 SB2022091454
#VU63075 - Permissions, Privileges, and Access Controls
CVE-2022-0026
CWE-264 Low
No
No
CU-330 11.05.2022 SB2022051127
#VU63074 - Uncontrolled Search Path Element
CVE-2022-0025
CWE-427 Low
No
No
CU-500, 7.7.1.62043 11.05.2022 SB2022051127
#VU59546 - Uncontrolled Search Path Element
CVE-2022-0015
CWE-427 Medium
No
No
5.0.12, 6.1.9 12.01.2022 SB2022011214
#VU59545 - Untrusted Search Path
CVE-2022-0014
CWE-426 Low
No
No
5.0.12, 6.1.9, 7.2.4, 7.3.2 12.01.2022 SB2022011214
#VU59544 - File And Directory Information Exposure
CVE-2022-0013
CWE-538 Low
No
No
5.0.12, 6.1.9, 7.2.4, 7.3.2 12.01.2022 SB2022011214
#VU59543 - Improper Link Resolution Before File Access ('Link Following')
CVE-2022-0012
CWE-59 Low
No
No
5.0.12, 6.1.9, 7.2.4, 7.3.2 12.01.2022 SB2022011214
#VU54881 - Uncontrolled Search Path Element
CVE-2021-3042
CWE-427 Low
No
No
6.1 with content update 181, 7.2 with content update 181, 7.3 with content update 181 15.07.2021 SB2021071507


Showing elements 1 - 20 out of 23