Prisma Access Agent: Improper Certificate Validation on iOS
Plan PatchCVSS 8.7CVE-2026-0277Jul 8, 2026
Palo Alto NetworksTransportation
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
The Prisma Access Agent for iOS contains an improper certificate validation flaw that allows an attacker with network position to perform a man-in-the-middle attack and intercept VPN traffic. The vulnerability affects iOS versions below 26.2.1. Windows, macOS, Linux, Android, and ChromeOS versions are not affected.
What this means
What could happen
An attacker with network position between a user and the VPN endpoint could intercept and decrypt VPN traffic on iOS devices, potentially exposing sensitive communications and credentials from transportation networks.
Who's at risk
This affects transportation organizations and any enterprise using Prisma Access Agent on iOS devices for VPN connectivity. Mobile workers, field personnel, and remote users in transportation operations who rely on iOS devices for secure network access are at risk.
How it could be exploited
An attacker positioned on the network path (such as a rogue WiFi access point or compromised router) could present a fraudulent certificate to the Prisma Access Agent on iOS. The agent would accept the certificate without proper validation, allowing the attacker to intercept and decrypt all VPN traffic from that device.
Prerequisites
- Network position between iOS device and VPN endpoint (e.g., rogue WiFi, compromised network segment)
- Ability to present a fraudulent SSL/TLS certificate to the iOS device
remotely exploitableman-in-the-middle attackVPN traffic interceptionaffects mobile workers
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (6)
1 with fix5 pending
ProductAffected VersionsFix Status
Prisma Access AgentBelow 26.2.1 on iOS26.2.1 on iOS+
Prisma Access AgentNone on LinuxNo fix yet
Prisma Access AgentNone on WindowsNo fix yet
Prisma Access AgentNone on macOSNo fix yet
Prisma Access AgentNone on AndroidNo fix yet
Prisma Access AgentNone on ChromeOSNo fix yet
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict iOS devices to trusted WiFi networks and avoid public/open networks until patched
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Prisma Access Agent
HOTFIXUpdate Prisma Access Agent on all iOS devices to version 26.2.1 or later
Long-term hardening
0/1HARDENINGImplement network monitoring to detect certificate spoofing or unusual VPN connection patterns
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/84d26ef3-1c25-4ca9-a727-2d25f093ac53Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.