Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
Problem types
CWE-15: External Control of System or Configuration Setting
Product status
9.1.0 (custom) before 5.10.14
9.0 (custom)
8.9 (custom)
8.7-CE (custom)
9.0 (custom) before 9.0.1
8.9 (custom) before 8.9.1
8.7-CE (custom) before 8.7.101-CE
8.3-CE (custom) before 8.3-CE-CU-2120
7.9-CE (custom) before 7.9-CE-CU-2120
Timeline
| 2026-04-08: | Initial publication. |
Credits
WhatThe0xDoin
References
security.paloaltonetworks.com/CVE-2026-0232
