Secure Remote Access / VPN · head-to-head
OpenVPN vs Palo Alto Networks
SSL/IPsec VPN gateways and ZTNA appliances. Counts are scoped to this segment and the selected published-date window. OpenVPN carries 3.8× the disclosed CVE volume of Palo Alto Networks. Volume reflects disclosure practice and install base as much as code quality — read it with the severity mix. Sourced from the NIST NVD; lower counts indicate a smaller disclosed vulnerability surface — not necessarily lower risk.
Disclosure record
Bars are normalized per row to the larger value; the leading count is emphasized.
| OpenVPN | Metric | Palo Alto Networks | ||
|---|---|---|---|---|
| 15 | Total CVEs | 4 | ||
| 2 | Critical | 0 | ||
| 9 | High | 2 | ||
| 4 | Medium | 2 | ||
| 0 | Low | 0 | ||
| 29 | Open in latest | 13 |
Risk profile
Each severity band as a share of the vendor's own total — strips out raw volume so the profiles compare directly.
OpenVPN
13.3% critical- Critical
- 213.3%
- High
- 960.0%
- Medium
- 426.7%
- Low
- 00.0%
Palo Alto Networks
0.0% critical- Critical
- 00.0%
- High
- 250.0%
- Medium
- 250.0%
- Low
- 00.0%
Recent activity
Latest in-window disclosures per vendor, newest first. Each ID links to its NVD record.
OpenVPN
| CVE | Severity | CVSS | Published |
|---|---|---|---|
| CVE-2026-13379(opens NVD record) | Critical | 9.1 | Jul 30, 2026 |
| CVE-2026-13117(opens NVD record) | High | 8.1 | Jul 30, 2026 |
| CVE-2026-12996(opens NVD record) | High | 8.1 | Jul 30, 2026 |
| CVE-2026-12932(opens NVD record) | High | 8.1 | Jul 30, 2026 |
| CVE-2026-11771(opens NVD record) | High | 7.5 | Jul 30, 2026 |
| CVE-2025-3110(opens NVD record) | High | 7.5 | Jul 8, 2026 |
Palo Alto Networks
| CVE | Severity | CVSS | Published |
|---|---|---|---|
| CVE-2026-0267(opens NVD record) | Medium | 5.5 | Jun 10, 2026 |
| CVE-2026-0251(opens NVD record) | High | 7.8 | May 13, 2026 |
| CVE-2026-0250(opens NVD record) | High | 8.1 | May 13, 2026 |
| CVE-2026-0249(opens NVD record) | Medium | 6.5 | May 13, 2026 |
Track new CVEs for these vendors
Get an email the moment a new vulnerability is disclosed for the products you rely on.