Troubleshooting "Vulnerability issues daily limit reached" in Cortex Cloud

Troubleshooting "Vulnerability issues daily limit reached" in Cortex Cloud

147
Created On 06/18/26 10:13 AM - Last Modified 07/27/26 16:42 PM


Symptom


Users receive a notification stating "Vulnerability issues daily limit reached" or "Vulnerability issues creation paused." 



Environment


  • Cortex Cloud / XSIAM / XDR


Cause


Cortex Cloud has a hard-coded daily quota of 50,000 vulnerability issue actions per domain.

  • Action Types: The limit is consumed by the creation of new issues, status changes (e.g., "New" to "In Progress"), and policy re-evaluations (When modifying or creating new vulnerability policies)

  • Volume: A single asset can trigger thousands of individual findings. When processed globally, these frequently exceed the 50,000 action threshold.

  • Scope: This is a platform-wide limit. It is not tenant-specific and cannot be adjusted on a per-customer basis at this time.



Resolution


While global limit increases are being considered for future releases, TSEs should advise customers to prioritize high-value data within the existing quota:

  1. Enable "CVEs Confirmed Vulnerable Externally": Engineering recommends enabling this specific default policy. It ensures that the daily quota is used to promote the most critical, externally validated risks (AST findings) to "Issues."

  2. Disable Broad/Noisy Policies: Advise the customer to disable or narrow the scope of broad policies (e.g., policies covering all "Medium" or "Low" severity CVEs) that generate high volumes of low-value issues.

  3. Targeted Asset Scoping: Refine policies to target only the most important assets or asset groups to ensure generated issues are meaningful.

  4. Findings-First Workflow: Suggest using the Vulnerability Findings view for raw data visibility. Discovery and prevention functions are not affected by the issue creation pause, the environment remains protected.

  5. CS Engagement: If the customer requires hands-on assistance with policy refinement or scoping, refer them to their Customer Success (CS) team.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000oMhNKAU&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail