ZeroHour
GBHackerspublished ()ingested Divya
Part of a story covered by 3 sources: “Palo Alto Networks patches unauthenticated PAN-OS XML buffer overflow CVE-2026-0310 enabling root code execution on PA-Series firewalls” — merged summary and timeline →

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

AI summary · glm-5.3-flash

Palo Alto Networks fixed CVE-2026-0310, a CVSS 9.2 unauthenticated PAN-OS buffer overflow enabling root code execution on PA-Series firewalls.

Palo Alto Networks published an advisory on September 9, 2026 for CVE-2026-0310, a CWE-787 out-of-bounds write in PAN-OS XML processing with a CVSS v4.0 base score of 9.2, affecting the management and dataplane interfaces. Unauthenticated attackers could execute arbitrary code as root on PA-Series hardware firewalls, while VM-Series faces denial-of-service impact and Prisma Access and Cloud NGFW have reduced, authenticated exposure. Affected releases include PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2 before fixed maintenance releases such as 12.2.3, 12.1.4-h10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; no workaround is available. Palo Alto is not aware of malicious exploitation but classifies remediation urgency as highest.

  • CVE-2026-0310 (CWE-787, CVSS 9.2) stems from unsafe XML handling and needs no special configuration or authentication.
  • PA-Series firewalls face root-level code execution; VM-Series limited to denial of service; Prisma Access needs authentication.
  • Affected branches: PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2, with fixed releases across all trains.
  • No workaround exists; Palo Alto recommends restricting management access to trusted IPs or a dedicated jump box.
  • No malicious exploitation observed so far, but unauthenticated root RCE on perimeter firewalls warrants urgent patching.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0310
Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls

Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven).

Do: Patch to a fixed PAN-OS release as soon as Palo Alto Networks publishes fixed versions, prioritizing PA-Series firewalls and Panorama where root code execution is possible; the advisory does not name specific fixed builds, so consult the vendor advisory for branch-specific updates. Until patching, restrict access to the management web and dataplane interfaces to trusted internal IP addresses per the vendor's management-access hardening guidance, and audit which firewalls, VM-Series instances, and Panorama servers have these interfaces reachable from untrusted networks. Monitor Palo Alto Networks advisories for updates on exploitation status and proof-of-concept releases.

7.2
  • Palo Alto Networks PAN-OS on PA-Series firewalls
  • Palo Alto Networks PAN-OS on VM-Series firewalls
  • Palo Alto Networks Panorama
largetens of thousands of exposed PAN-OS systems (public internet scans have historically shown on the order of 10,000-50,000 PAN-OS management and dataplane…
Full article529 words · extracted from gbhackers.com · click to collapse

Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls.

This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces.

The advisory, published on September 9, 2026, assigns a CVSS v4.0 base score of 9.2 and a CVSS-BT score of 7.2. Palo Alto Networks has classified its recommended remediation urgency as “highest.”

Palo Alto PAN-OS Buffer Overflow

CVE-2026-0310 is categorized as CWE-787, which refers to an out-of-bounds write vulnerability. The issue arises from unsafe XML handling, leading to a buffer overflow that a remote attacker could trigger without authentication, special privileges, user interaction, or specific configurations.

If exploited on PA-Series appliances, the vulnerability could allow arbitrary code execution with root privileges. Gaining root access to a perimeter firewall poses a significant risk, as an intruder could alter security policies, disable protections, intercept or manipulate network traffic, establish persistence, or use the device as an internal pivot point.

The vulnerability affects Palo Alto Networks products in different ways:

Product typePotential impactSeverity
PA-Series firewallsArbitrary code execution as rootHigh
VM-Series firewallsDenial-of-service conditionMedium
Prisma Access and Cloud NGFWReduced exposure; authenticated access requiredMedium

Palo Alto Networks indicates the risk is highest for PA-Series hardware firewalls because of potential code execution. In contrast, VM-Series firewalls’ impact is limited to denial of service, which, while less severe, can still disrupt critical business connectivity and inspection functions.

Affected PAN-OS Releases

The vulnerability affects PAN-OS versions 10.2, 11.1, 11.2, 12.1, and 12.2 before specific fixed maintenance releases. Users of PAN-OS 12.2 should upgrade to version 12.2.3 or later.

Organizations on PAN-OS 12.1 should upgrade to either 12.1.4-h10, 12.1.7-h5, or 12.1.10, depending on their supported maintenance train. Fixed versions are also available for PAN-OS branches 11.2, 11.1, and 10.2, specifically 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10.

Unsupported PAN-OS releases remain vulnerable, and users are encouraged to migrate to a supported fixed version. Palo Alto Networks has stated that no special configuration is necessary for a device to be vulnerable.

No workaround is currently available, so software updates are the primary remediation. Administrators should prioritize patching internet-exposed PA-Series firewalls and ensure that management interfaces are not accessible from untrusted networks.

Palo Alto Networks recommends limiting management access to trusted internal IP addresses. Ideally, a dedicated jump box should be the only system allowed to access the management interface, reducing the reachable attack surface before completing the upgrade.

Security teams are advised to review administrative access rules, the exposure of HTTPS and management services, recent configuration changes, unexpected firewall restarts, and anomalous XML-related requests.

While Palo Alto Networks is not aware of any malicious exploitation at this time, the combination of unauthenticated access and potential root-level code execution underscores the necessity for rapid patching.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/palo-alto-pan-os-buffer-overflow/