CVE-2026-0237
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to a
CVSS
7.8
High
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: May 13, 2026 · Last modified: Jul 14, 2026 · CWE-424
0.1%EPSS · 30 days0.1%
2026-08-022026-08-31
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-584286.5 MED25.7%
——8Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)5dCVE-2026-667569.8 CRI37.1%
——11Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.21dCVE-2026-02684.4 MED0.7%
——0A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.
This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.39d