Known vulnerabilities in Cortex XSOAR

Software: Cortex XSOAR
Software CPE: cpe:2.3:a:palo_alto_networks:cortex_xsoar:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cortex XSOAR Cortex XSOAR is affected by 13 known vulnerabilities: 4 high, 3 medium, 6 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134590 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-0270
CWE-22 Medium
No
No
8.13.1 16.06.2026 SB2026061638
#VU125523 - Improper Verification of Cryptographic Signature
CVE-2026-0234
CWE-347 High
No
No
1.5.52 09.04.2026 SB2026040905
#VU98347 - Improper Access Control
CVE-2024-9470
CWE-284 Low
No
No
6.12.0 1271551 10.10.2024 SB2024101020
#VU82924 - Permissions, Privileges, and Access Controls
CVE-2023-3282
CWE-264 Low
No
No
6.10. 250144 09.11.2023 SB2023110903
#VU72067 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-0003
CWE-22 Medium
No
No
6.6 186115, 6.8 185719, 6.9 185415, 6.10.0 185964 08.02.2023 SB2023020866
#VU69191 - Insufficient Verification of Data Authenticity
CVE-2022-0031
CWE-345 Low
No
No
6.9.0 130766 09.11.2022 SB2022110961
#VU63076 - Improper Access Control
CVE-2022-0027
CWE-284 Medium
No
No
6.6.0 2585049 11.05.2022 SB2022051128
#VU60482 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-0020
CWE-79 Low
Available
No
6.2.0 1958888 09.02.2022 SB2022020927
#VU56411 - Improper Verification of Cryptographic Signature
CVE-2021-3051
CWE-347 High
No
No
5.5.0 1578677, 6.0.2 1576452, 6.1.0 1578663, 6.2.0 1578666 08.09.2021 SB2021090823
#VU56410 - Improper Access Control
CVE-2021-3049
CWE-284 Low
No
No
6.1.0 1209934 08.09.2021 SB2021090822
#VU54313 - Improper Authorization
CVE-2021-3044
CWE-285 High
No
No
6.1.0 271064, 6.2.0 1271065 22.06.2021 SB2021062225
#VU51415 - Information Exposure Through Log Files
CVE-2021-3034
CWE-532 Low
No
No
5.5 build 98622, 6.0.1 build 830029, 6.0.2 build 98623, 6.1.0 build 848144 11.03.2021 SB2021031113
#VU50496 - Improper input validation
CVE-2021-26701
CWE-20 High
No
No
7.1.3.20270 09.02.2021 SB2021020950
SB2021031210
SB2021031211
and 18 more