CVE-2026-0234Disclosure(paloaltonetworks / cortex_xsiam)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch paloaltonetworks cortex_xsiam systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cortex_xsiam
  • cortex_xsoar

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-04-09); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Products
cortex_xsiamcortex_xsoar

Deep dive

Activity timeline11 mentions / 8d
01122Mentions · 2026-04-08: 1Mentions · 2026-04-09: 2Mentions · 2026-04-10: 2Mentions · 2026-04-13: 2Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-04-19: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-04-09: 2Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 2Technical Details · 2026-04-13: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-25: 104-0804-0904-1004-1304-1404-1604-1904-25
Signal classification3 categories
Disclosure
654.5%
Patch
327.3%
General
218.2%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-092
Patch2
2026-04-102
General1Patch1
2026-04-132
Disclosure2
2026-04-141
Disclosure1
2026-04-161
Disclosure1
2026-04-191
General1
2026-04-251
Disclosure1
Full discourse11 posts
  • Cyber Security News@The_Cyber_News
    Patch

    🛡️ Palo Alto Cortex Microsoft Teams Integration Vulnerability Enables Data Access for Attackers Source: https://cybersecuritynews.com/palo-alto-cortex-microsoft-teams-integration/ Palo Alto Networks released an urgent update to patch a high-severity flaw (CVE-2026-0234) affecting the Microsoft Teams integration in Cortex XSOAR and Cortex XSIAM. This flaw could allow unauthorized attackers to access and modify sensitive data, prompting Palo Alto Networks to issue a “Highest” urgency alert to its users. Because the Microsoft Teams integration fails to inspect these digital passports properly, an attacker can effectively forge a fake signature to trick the system. By spoofing this signature, an attacker can bypass security checkpoints entirely. They do not need a valid username or password or any prior network privileges. #cybersecuritynews

    Post summary

    Palo Alto Networks released an urgent patch for CVE-2026-0234 that fixes a flaw allowing attackers to forge digital signatures for Microsoft Teams integration and bypass security checks.

    330086316.2K
    66.3K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Palo Alto Cortex の脆弱性 CVE-2026-0234 が FIX:Teams との連携不備による不正アクセス https://iototsecnews.jp/2026/04/09/palo-alto-cortex-xsoar-flaw-in-microsoft-teams-integration-lets-attackers-access-data/ Palo Alto Networks の Cortex XSOAR/XSIAM が、Microsoft Teams と連携する際の不適切な暗号署名の検証 (CWE-347) という脆弱性が発生しています。その通信が本物であることを証明する検証プロセスの不備を突く攻撃者は、身元を偽装してシステムをだますことが可能になっています。この脆弱性 CVE-2026-0234 が悪用されると、攻撃者はユーザー名やパスワードなしでシステムへ侵入し、インシデント対応の自動化設定の改竄や、機密データへの不正アクセスを可能にします。ご利用のチームは、ご注意ください。 #Cortex #CVE20260234 #PaloAlto #Vulnerability

    Post summary

    The article announces a new vulnerability (CVE‑2026‑0234) in Palo Alto Cortex XSOAR where improper Microsoft Teams integration allows attackers to spoof credentials and access system data, underscoring the need for users to remain vigilant.

    01010192
    484 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Palo Alto Networks patches critical CVE-2026-0234 in Cortex XSOAR and XSIAM Microsoft Teams integration, fixing flaw that let unauthenticated attackers access and modify sensitive data. https://threatcluster.io/cluster/palo-alto-cortex-xsoar-vulnerability-in-microsoft-teams-inte-31b1c5ce

    Post summary

    Palo Alto Networks issued a patch for CVE‑2026‑0234, which allowed unauthenticated attackers to access and modify sensitive data in its Microsoft Teams integration.

    0002086
    378 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    ⚠️ High severity bug (CVE-2026-0234) in Cortex XSOAR/XSIAM Teams integration could let attackers access & modify data without auth. No active exploits yet, but patch ASAP to 1.5.52+. No workaround available. Source: https://security.paloaltonetworks.com/CVE-2026-0234 #CyberSecurity

    Post summary

    CVE-2026-0234 presents a high‑severity flaw that permits unauthenticated data access or modification in Cortex XSOAR/XSIAM Teams integration, with Palo Alto advising a patch to 1.5.52+ and noting no known active exploitation.

    00020103
    739 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Palo Alto ❗ CVE-2026-0234 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-palo-alto/ https://t.co/Vocmg9p7wM

    Post summary

    A new vulnerability (CVE‑2026‑0234) affecting Palo Alto products is disclosed, with links for further details but no additional technical or exploit information.

    00010104
    6.7K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration (CVE-2026-0234) #CortexXSIAM #CortexXSOAR #CVE20260234 #CyberSecurity https://www.systemtek.co.uk/?p=50812 https://t.co/Jp0kIc9L4k

    Post summary

    The tweet announces the discovery of CVE-2026-0234, highlighting an improper verification of cryptographic signatures in the Cortex XSOAR Microsoft Teams integration.

    0000034
    1.8K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-0234: Improper Cryptographic Signature Verification - What It Means for Your Business and How to Respond https://hubs.li/Q04cF1Bm0

    Post summary

    The provided text is a brief title linking to an article about CVE-2026-0234, identifying it as an improper cryptographic signature verification issue but providing no PoC, exploit, patch, or active exploitation details.

    0000036
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0234 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables a… https://www.cve.org/CVERecord?id=CVE-2026-0234

    Post summary

    A CVE record reports an improper verification of cryptographic signature vulnerability in Cortex XSOAR and XSIAM during Microsoft Teams integration, with no additional exploit details or remediation steps provided.

    00000131
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0234 Improper Cryptographic Signature Verification in Palo Alto Cortex XSOAR a... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0234 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces CVE-2026-0234, describing an improper cryptographic signature verification issue in Palo Alto Cortex XSOAR and provides a link to generic vulnerability details.

    0000054
    4.0K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 Palo Alto Cortex Teams Integration Flaw: Forged #Digital Passports Let Attackers Hijack Sensitive Data (#CVE-2026-0234) + Video https://undercodetesting.com/palo-alto-cortex-teams-integration-flaw-forged-digital-passports-let-attackers-hijack-sensitive-data-cve-2026-0234-video/ Educational Purposes!

    Post summary

    The article highlights an authentication flaw where forged digital passports can lead to data hijacking in Palo Alto Cortex Teams, but it does not provide exploit code, active exploitation evidence, or patch details.

    0000052
    464 followersView on X
  • まっちゃだいふく@ripjyr
    Disclosure

    Paloaltoの脆弱性情報 「CVE-2026-0234 Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration (Severity: HIGH)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0234

    Post summary

    The snippet announces the publication of CVE-2026-0234, detailing a high‑severity cryptographic signature verification flaw in Palo Alto Cortex XSOAR's Microsoft Teams integration, without providing proof‑of‑concepts, exploits, or patches.

    00000319
    8.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppaloaltonetworkscortex_xsiam---
Apppaloaltonetworkscortex_xsoar---

Explore more