ZeroHour
Product

PA-Series

2 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks fixed CVE-2026-0310, a CVSS 9.2 unauthenticated PAN-OS buffer overflow enabling root code execution on PA-Series firewalls.

Palo Alto Networks published an advisory on September 9, 2026 for CVE-2026-0310, a CWE-787 out-of-bounds write in PAN-OS XML processing with a CVSS v4.0 base score of 9.2, affecting the management and dataplane interfaces. Unauthenticated attackers could execute arbitrary code as root on PA-Series hardware firewalls, while VM-Series faces denial-of-service impact and Prisma Access and Cloud NGFW have reduced, authenticated exposure. Affected releases include PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2 before fixed maintenance releases such as 12.2.3, 12.1.4-h10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; no workaround is available. Palo Alto is not aware of malicious exploitation but classifies remediation urgency as highest.

GBHackersupdated · 5d agofirst · 5d agoVulnerability 3 sourcesCVE-2026-0310

Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

Palo Alto Networks patched CVE-2026-0310, an unauthenticated XML-processing buffer overflow in PAN-OS allowing root code execution on PA-Series firewalls.

Palo Alto Networks disclosed CVE-2026-0310, an out-of-bounds write (CWE-787) in PAN-OS XML processing with a CVSS-B base score of 9.2 and CVSS-BT of 7.2. An unauthenticated attacker with network access to a vulnerable management or dataplane interface can send crafted XML to execute arbitrary code as root on PA-Series appliances. On VM-Series the impact is limited to denial-of-service, while Prisma Access and Cloud NGFW require authentication and carry lower risk. Fixed releases include 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; no workaround exists beyond restricting management interface access.

Cyber Security Newsupdated · 5d agofirst · 5d agoVulnerability 3 sourcesCVE-2026-0310

2026-006: Critical Vulnerability in PAN-OS

Palo Alto Networks PAN-OS User-ID Authentication Portal flaw allows unauthenticated root RCE; limited exploitation observed and patches still pending.

Palo Alto Networks disclosed CVE-2026-0300 (CVSS 9.3), a buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) that enables unauthenticated arbitrary code execution with root privileges on PA-Series and VM-Series firewalls. Only appliances configured to use the Authentication Portal are affected. Palo Alto observed limited exploitation; at publication patches were not yet available, so restricting portal access to trusted zones or disabling it was recommended as mitigation.

CERT-EU Advisories · Jun 5, 2026Vulnerability in the wildCVE-2026-0300

Related CVEs

  • Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls
    Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven).
    · Palo Alto Networks PAN-OS on PA-Series firewalls · Palo Alto Networks PAN-OS on VM-Series firewallslarge
  • Unauthenticated Out-of-bounds Write RCE in Palo Alto Networks PAN-OS
    Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability (CWE-787) in the User-ID Authentication Portal, also known as the Captive Portal service. An unauthenticated attacker can trigger the flaw by sending specially crafted packets to the portal, without needing valid credentials. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the firewall, giving full control of PA-Series and VM-Series devices. Any organization running PA-Series or VM-Series firewalls with the User-ID Authentication Portal service enabled is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-06, indicating exploitation in the wild; EPSS puts the 30-day exploitation probability at 31.7% (98th percentile), patches were released on 2026-05-13, no public PoC is known, and CVSS scoring is not yet available.
    · Palo Alto Networks PAN-OS KEVlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.