Known vulnerabilities in Palo Alto PAN-OS 11.1.6-h36

Version: 11.1.6-h36
Software CPE: cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Palo Alto PAN-OS version 11.1.6-h36 Palo Alto PAN-OS 11.1.6-h36 is affected by 3 vulnerabilities: 1 high, 2 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU149499 - Untrusted Search Path
CVE-2026-0307
CWE-426 Low
No
No
10.2.7-h37, 10.2.10-h40, 10.2.13-h24, 10.2.16-h10, 10.2.18, 10.2.18-h10, 11.1.4-h36, 11.1.6-h38, 11.1.7-h10, 11.1.10-h33, 11.1.13-h12, 11.1.16, 11.1.16-h2, 11.2.4-h21, 11.2.7-h20, 11.2.10-h14, 11.2.13-h2, 12.1.4-h10, 12.1.7-h5, 12.1.10, 12.2.3 14.09.2026 SB2026091428
#VU149495 - Out-of-bounds write
CVE-2026-0310
CWE-787 High
No
No
10.2.7-h37, 10.2.10-h40, 10.2.13-h24, 10.2.16-h10, 10.2.18-h10, 11.1.4-h36, 11.1.6-h38, 11.1.7-h10, 11.1.10-h33, 11.1.13-h12, 11.1.16-h2, 11.2.4-h21, 11.2.7-h20, 11.2.10-h14, 11.2.13-h2, 12.1.4-h10, 12.1.7-h5, 12.1.10, 12.2.3 14.09.2026 SB2026091426
#VU149494 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-0309
CWE-78 Low
No
No
10.2.7-h37, 10.2.10-h40, 10.2.13-h24, 10.2.16-h10, 10.2.18-h10, 11.1.4-h36, 11.1.6-h38, 11.1.7-h10, 11.1.10-h33, 11.1.13-h12, 11.1.16-h2, 11.2.4-h21, 11.2.7-h20, 11.2.10-h14, 11.2.13-h2, 12.1.4-h10, 12.1.7-h5, 12.1.10, 12.2.3 14.09.2026 SB2026091426