CVE-2026-0232 is a protection mechanism bypass vulnerability affecting the Palo Alto Networks Cortex XDR agent on Windows systems. The flaw allows a local Windows administrator to disable the agent, potentially allowing malware to operate without detection. This vulnerability specifically impacts endpoint detection and response capabilities on Windows platforms. The attack requires local administrator-level privileges, indicating moderate attack complexity and limiting the threat to trusted users or compromised administrative accounts. The potential impact is significant, as successful exploitation would eliminate security monitoring and detection mechanisms on affected endpoints, enabling undetected malicious activity. The vulnerability currently shows no evidence of active exploitation in the wild. It does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on security hotlists. The EPSS score of 0.00017 indicates minimal real-world exploitation activity, and community attention remains limited at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.7.0, < 8.7.101CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:* | ||
7.9CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.9:*:*:*:critical_environment:*:*:* | ||
8.3CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.3:*:*:*:critical_environment:*:*:* | ||
8.9.0CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.9.0:-:*:*:-:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:9.0.0:-:*:*:-:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.