New Features in July 2026
Focus
Focus
Advanced Threat Prevention Powered by Precision AI®

New Features in July 2026

Table of Contents

New Features in July 2026

Review the new features and platform changes for Advanced Threat Prevention in July 2026.

Activity Insights: Threats Dashboard Improvements

July, 2026
Quantifying the specific protective value of Palo Alto Networks Advanced Security subscriptions, including Advanced Threat Prevention, Advanced URL Filtering, Advanced WildFire, and Advanced DNS Security, often requires manual correlation across fragmented views. This lack of clear attribution makes it difficult to understand how specialized services protect against unique, emerging threats compared to standard signatures.
You can now utilize the Activity Insights: Threats dashboard in Strata Cloud Manager to visualize the precise impact of your security subscriptions. This interface introduces platform effects metrics, demonstrating how shared intelligence from the global customer base and cross-service correlations automatically block patient-zero attacks in your environment. Detailed visualizations allow you to track trends in advanced threats, distinguishing between known signature-based blocks and novel attacks detected by cloud-based machine learning features.
The dashboard now provides a Threat | CVE toggle, giving you visibility into CVE exploits detected by Advanced Threat Prevention alongside your existing threat activity views. The CVE view helps you identify which real-world CVE exploits are targeting your environment, whether they are being blocked or alerted, and how to prioritize remediation using severity and exploitability metrics such as CVSS scores, EPSS scores, and exploit status.
Additionally, the Threat Search page now supports both Threat ID and CVE search, allowing you to investigate specific threat signatures or CVE exploits directly from the dashboard workflow. You can search by Threat ID to examine detection patterns for a specific signature, or search by CVE identifier to view all related threat activity, CVSS and EPSS metrics, and firewall coverage for that vulnerability.
By differentiating these protection sources and correlating CVE exploit data with your network activity, you can validate the specific return on investment of your subscriptions and gain deeper visibility into the sophisticated threat vectors targeting your network.

Enhanced Content Cloud Analysis Transport Support

July, 2026
Palo Alto Networks introduces a redesigned transport architecture for cloud-delivered security services that eliminates performance bottlenecks in the Multi Inline Cloud Analysis (MICA) data forwarding channel. This architecture improves inline cloud analysis for Enterprise DLP, Advanced Threat Prevention, Advanced URL Filtering, Advanced WildFire, Prisma AIRS (AI Runtime Security), and ACE (App-ID Cloud Engine) when used alongside SaaS Security Inline, and AI Access Security.
The new architecture removes the fixed-core transport limitation that previously constrained cloud submission throughput regardless of available hardware resources. All data plane cores now natively handle payload forwarding to the cloud through a scalable connection pool. Each connection is established directly from the data plane over TLS, eliminating the intermediate process that previously serialized all cloud submissions through a single core.
The redesigned transport reduces latency by replacing protocol translation layers with a direct binary protocol between the data plane and advanced service addresses. Native PAN-OS memory pools replace the previously fixed-size memory allocation, reducing dedicated memory consumption and increasing overall system capacity. The newly introduced Advanced Forwarding discovery service dynamically assigns advanced service addresses based on your NGFW's location and configuration, improving reliability and enabling automatic failover without manual intervention.
When Advanced Forwarding is enabled, the NGFW establishes TLS connections directly from the data plane to the cloud. To use the legacy transport instead of Advanced Forwarding, you must manually disable Advanced Forwarding. The NGFW does not automatically fall back to the legacy transport method.

Advanced Threat Prevention Local Deep Learning Support for Command Injection

July, 2026
While inline cloud analysis for Advanced Threat Prevention provides robust command injection protection, it can restrict traffic volume and introduce 100–200 milliseconds of latency—challenging for high-throughput environments. Local Deep Learning for command injection resolves this by running the Palo Alto Networks deep learning model directly on supported NGFWs. This allows you to inspect significantly more inbound traffic locally, delivering verdicts up to 100 times faster than cloud-only analysis.
Local Deep Learning for command injection uses the same proven model that runs in the Advanced Threat Prevention cloud, optimized for on-device execution through new CPU instruction sets and memory-efficient model loading. You configure the feature in the Vulnerability Protection profile under the Inline Cloud Analysis tab—a new Local Deep Learning column lets you enable or disable the feature for the command injection ML model. Local Deep Learning is enabled by default when you enable Inline Cloud Analysis on a new Vulnerability Protection profile, giving you immediate command injection protection without additional configuration.
During operation, the NGFW evaluates suspicious HTTP traffic against the local model and processes benign verdicts instantaneously. If the model identifies a potential command injection exploit, it forwards the traffic to the cloud for a false-positive check and returns the cloud verdict when available. If the cloud is unreachable or times out, the NGFW uses the local model verdict and takes the action you configured—eliminating the fail-open gap where threats could pass uninspected. A new local packet capture option lets you retain forensic evidence for detections made when the cloud is non-responsive.
Content updates deliver the latest command injection models automatically, keeping your on device detection current without manual intervention.

PAN-OS Shield Support for Vulnerability Protection

July, 2026
  • In the PAN-OS 12.2.2 release, PAN-OS Shield is only supported for protecting GlobalProtect gateway and portal.
To ensure continual protection against critical vulnerabilities and exploits targeting your firewall, Palo Alto Networks introduces PAN-OS Shield, a built-in feature that uses Advanced Threat Prevention (ATP) to provide inline protections.
These vulnerability protection signatures are delivered via a PAN-OS Shield module as part of the standard Applications and Threats Content Package. PAN-OS Shield applies these critical vulnerability updates automatically, independent of PAN-OS release cycles, and requires no NGFW restarts or operational downtime. This automatic security update capability is built into all platforms by default and does not require an active Advanced Threat Prevention license for PAN-OS specific vulnerability protections. Additionally, when malicious traffic is detected, the NGFW executes the action defined within the PAN-OS Shield security policy and its associated vulnerability protection profile. Additionally, the NGFW automatically generates a standard Threat Log detailing the event.
To provide immediate protection out of the box, Palo Alto Networks recommends enabling PAN-OS Shield, which requires a commit, followed by a system reboot. While the base policy name and description of the pre-configured PAN-OS Shield profile cannot be modified, administrators retain the flexibility to handle false positives. If you need to bypass a specific vulnerability signature for your environment, you can navigate to your security profiles and open the built-in PAN-OS Shield Vulnerability Profile to modify its threat exceptions. When adding exceptions, you can easily filter and search specifically for "Palo Alto Networks" signatures associated with the PAN-OS Shield service.
In the rare circumstances that PAN-OS Shield blocks a benign web management session, you can choose to use the PAN-OS CLI or use a bastion machine with access to the console port or manage via interface management profile configured on a dataplane port. Check PAN-OS Shield logs to determine if this is the case and contact Customer Support.