Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
Problem types
CWE-754: Improper Check for Unusual or Exceptional Conditions
Product status
9.1.0 (custom)
9.0.0 (custom)
8.9.0 (custom)
8.7-CE (custom) before 8.7.101-CE
8.3-CE (custom) before 8.3.102-CE
Timeline
| 2026-03-11: | Initial publication. |
Credits
Michael Roitzsch, Barkhausen Institut gGmbH Carsten Weinhold, Barkhausen Institut gGmbH
References
security.paloaltonetworks.com/CVE-2026-0230