Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
Plan PatchCVSS 8.4CVE-2026-0278Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
What this means
What could happen
A local user on a Windows machine with Prisma Access Agent installed can bypass data loss prevention (DLP) policies, potentially allowing them to exfiltrate sensitive data that the organization intended to block.
Who's at risk
Windows endpoint users in any organization using Prisma Access Agent for secure remote access and data loss prevention. This affects finance, healthcare, government, and legal organizations that rely on DLP controls to protect sensitive documents, customer data, or intellectual property.
How it could be exploited
An attacker with local access to a Windows endpoint running vulnerable Prisma Access Agent can exploit weaknesses in the DLP protection mechanism to circumvent policy controls and transfer restricted data outside the organization's security boundaries.
Prerequisites
- Local user access to a Windows machine running vulnerable Prisma Access Agent version below 26.2.1
- DLP policies configured and enabled in Prisma Access Agent
Locally exploitableLow complexity attackAffects data protection controlsNo fix available for macOS variant
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (2)
1 with fix1 pending
ProductAffected VersionsFix Status
Prisma Access AgentBelow 26.2.1 on Windows26.2.1 on Windows+
Prisma Access AgentNone on macOSNo fix yet
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Prisma Access Agent
HOTFIXUpdate Prisma Access Agent on all Windows machines to version 26.2.1 or later
Long-term hardening
0/2HARDENINGReview and audit DLP policy configurations to ensure they are appropriate for your organization's data classification and risk tolerance
HARDENINGImplement endpoint monitoring and logging to detect suspicious data transfer attempts that may indicate DLP bypass attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f54147e5-5bc3-4c45-a6c7-b28241232385Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.