LATEST View all updates

CVE-2026-0306: Prisma Access Agent Affected Versions and Fix

CVE-2026-0306 affects Windows Prisma Access Agent below 26.2; admins should upgrade to 26.2 or later.

Windows enterprise endpoint receiving a security update for CVE-2026-0306 DLP bypass remediation

Signal Brief

  • CVE-2026-0306 affects Prisma Access Agent on Windows below version 26.2; upgrade affected endpoints to 26.2 or later.
  • Palo Alto Networks lists macOS, Linux, iOS, Android and ChromeOS as unaffected by this CVE.
  • There is no known workaround, and Palo Alto Networks currently says it is not aware of malicious exploitation.
  • Do not confuse this CVE's 26.2 fix boundary with separate Prisma Access Agent advisories that may require 26.2.1 or later.

CVE-2026-0306 affects Prisma Access Agent on Windows when the installed version is below 26.2. Palo Alto Networks says a local user with low privileges can bypass configured Endpoint Data Loss Prevention enforcement and potentially exfiltrate sensitive data. The vendor’s remediation boundary is clear: affected Windows agents should be upgraded to version 26.2 or later.

Palo Alto Networks currently lists macOS, Linux, iOS, Android and ChromeOS as unaffected by this CVE. It also says there is no known workaround and that it is not aware of malicious exploitation. That means the immediate administrator task is version verification and upgrade, not an assumption that every Prisma Access deployment is compromised.

CVE-2026-0306: which Prisma Access Agent versions are affected?

Windows versions below 26.2 are affected. Windows version 26.2 and later are listed as unaffected by CVE-2026-0306. The other platforms listed in Palo Alto Networks’ advisory are not affected by this CVE.

What CVE-2026-0306 allows

The vulnerability affects Endpoint DLP enforcement in Prisma Access Agent on Windows. According to Palo Alto Networks, a local user can bypass configured DLP controls and exfiltrate sensitive data from an affected endpoint.

This is important to distinguish from a remote network compromise. The vendor’s published scoring information describes the attack vector as local and the privileges required as low. TPS therefore does not describe CVE-2026-0306 as remotely exploitable or unauthenticated.

Which platforms need action?

Platform CVE-2026-0306 state Reader action
Windows below 26.2 Affected Upgrade to 26.2 or later.
Windows 26.2 or later Not affected by this CVE No CVE-2026-0306 version upgrade is required solely for this issue.
macOS Not affected No action specifically for CVE-2026-0306.
Linux Not affected No action specifically for CVE-2026-0306.
iOS Not affected No action specifically for CVE-2026-0306.
Android Not affected No action specifically for CVE-2026-0306.
ChromeOS Not affected No action specifically for CVE-2026-0306.

What administrators should do

Inventory Windows endpoints

Identify systems running Prisma Access Agent on Windows and record the installed agent version.

Find versions below 26.2

Any Windows deployment below 26.2 falls within the vendor’s affected range for CVE-2026-0306.

Upgrade affected agents

Move affected Windows endpoints to Prisma Access Agent 26.2 or later using the organization’s normal tested deployment process.

Verify the final version

Confirm the affected endpoint reports version 26.2 or later after remediation.

The controlling vendor advisory is available on the Palo Alto Networks security advisory page.

Is version 26.2 enough, or is 26.2.1 required?

For CVE-2026-0306 specifically, Palo Alto Networks lists Windows versions below 26.2 as affected and 26.2 or later as unaffected. That makes 26.2 the vendor-defined fixed boundary for this CVE.

Administrators may encounter a different minimum version while reviewing other Prisma Access Agent advisories. For example, the earlier CVE-2026-0278 advisory requires Prisma Access Agent 26.2.1 or later for its affected Windows versions. These are separate vulnerabilities with separate remediation boundaries.

If an endpoint is exposed to more than one applicable advisory, the practical remediation target should satisfy the strictest currently applicable vendor requirement rather than assuming that one CVE’s minimum version resolves every Prisma Access Agent issue.

Does CVE-2026-0306 require special configuration?

Palo Alto Networks states that no special configuration is required for the vulnerability to affect an eligible Windows deployment. The security consequence is tied to Endpoint DLP enforcement, but administrators should not assume that an unusual or custom setup is necessary before the issue matters.

Is there a workaround?

No known workaround is listed by Palo Alto Networks. The vendor remediation is to upgrade affected Windows agents to a fixed release.

TPS therefore does not recommend disabling DLP, changing unrelated security settings or applying an unofficial configuration change as a substitute for the vendor-defined upgrade.

Is CVE-2026-0306 actively exploited?

Not according to the current vendor advisory. Palo Alto Networks says it is not aware of malicious exploitation of CVE-2026-0306.

That statement is a current evidence state, not a permanent guarantee. If Palo Alto Networks, CISA or another authoritative source later reports exploitation, the risk and response priority would materially change and this page should be updated.

How severe is the vulnerability?

Palo Alto Networks rates CVE-2026-0306 as Medium and publishes a CVSS-BT score of 5.8. Its scoring reflects a local attack path with low privileges required. The potential security consequence is nevertheless material for organizations that depend on Endpoint DLP because successful exploitation can undermine configured data-loss-prevention controls and expose sensitive information.

Severity should therefore not be inflated into a Critical or remote-code-execution claim. The appropriate response is evidence-based version remediation.

How do you prove an endpoint is remediated?

For this CVE, the clearest remediation proof is the installed Prisma Access Agent version on the affected Windows endpoint. If the system reports 26.2 or later, it is outside the affected version range defined in the current CVE-2026-0306 advisory.

Organizations with deployment-management or endpoint-inventory systems should preserve their normal change and version records so they can distinguish machines that have completed the update from devices that remain below the fixed boundary.

Should teams investigate historical data loss?

The vendor currently says it is not aware of malicious exploitation, and the reviewed primary guidance does not provide a CVE-specific retrospective compromise-investigation procedure.

TPS therefore does not claim that organizations need a special CVE-2026-0306 forensic workflow. If an organization already has independent evidence of suspicious DLP bypass, unexpected data movement or another security incident, it should follow its existing incident-response and DLP investigation procedures rather than treating this article as incident-specific forensic guidance.

What could change next?

The key states to monitor are any revision to the affected or fixed version boundary, a newly published workaround, vendor detection or investigation guidance, confirmation of malicious exploitation or addition to an authoritative exploited-vulnerability catalogue.

Those developments belong on this same canonical URL because they would strengthen or alter the remediation answer for the same reader job.

Verification note

ThePulseSignal reviewed Palo Alto Networks’ CVE-2026-0306 advisory for the affected platforms, Windows version boundary, attack-vector information, remediation, workaround state and exploitation statement. TPS also compared the version boundary with Palo Alto Networks’ separate CVE-2026-0278 advisory to prevent the 26.2 and 26.2.1 remediation requirements from being conflated.

Limitations and unresolved facts

  • The exact publication clock for the September 9 vendor advisory was not established.
  • The number of organizations or endpoints still running an affected Windows version is unknown.
  • No reviewed primary source establishes real-world malicious exploitation at this time.
  • No CVE-specific retrospective forensic or detection procedure was identified in the reviewed primary guidance.
  • Future vendor revisions, exploitation reports or authoritative catalogue additions may change remediation priority.
Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance on CVE-2026-0306 and Prisma Access Agent remediation. Palo Alto Networks currently lists Windows versions below 26.2 as affected, says 26.2 or later is not affected, reports no known workaround and says it is not aware of malicious exploitation. Exploitation status, affected-version boundaries and vendor guidance can change. Verify the controlling Palo Alto Networks advisory and your deployed agent version before consequential security action.