Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User
Palo Alto Networks patched CVE-2026-0310, an unauthenticated XML-processing buffer overflow in PAN-OS allowing root code execution on PA-Series firewalls.
Palo Alto Networks disclosed CVE-2026-0310, an out-of-bounds write (CWE-787) in PAN-OS XML processing with a CVSS-B base score of 9.2 and CVSS-BT of 7.2. An unauthenticated attacker with network access to a vulnerable management or dataplane interface can send crafted XML to execute arbitrary code as root on PA-Series appliances. On VM-Series the impact is limited to denial-of-service, while Prisma Access and Cloud NGFW require authentication and carry lower risk. Fixed releases include 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; no workaround exists beyond restricting management interface access.
- Unauthenticated remote attacker gains root code execution via crafted XML on management or dataplane interfaces
- CVSS-B base score 9.2 and CVSS-BT 7.2; classified as CWE-787 out-of-bounds write
- VM-Series exploitation limited to denial-of-service; Prisma Access and Cloud NGFW require authentication
- Fixed in 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; no workaround available
- Vendor found the flaw internally; no known exploitation in the wild as of September 9, 2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-0310 | Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven). Do: Patch to a fixed PAN-OS release as soon as Palo Alto Networks publishes fixed versions, prioritizing PA-Series firewalls and Panorama where root code execution is possible; the advisory does not name specific fixed builds, so consult the vendor advisory for branch-specific updates. Until patching, restrict access to the management web and dataplane interfaces to trusted internal IP addresses per the vendor's management-access hardening guidance, and audit which firewalls, VM-Series instances, and Panorama servers have these interfaces reachable from untrusted networks. Monitor Palo Alto Networks advisories for updates on exploitation status and proof-of-concept releases. | 7.2 | — |
| largetens of thousands of exposed PAN-OS systems (public internet scans have historically shown on the order of 10,000-50,000 PAN-OS management and dataplane… |
Full article446 words · extracted from cybersecuritynews.com · click to collapse
Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls.
Tracked as CVE-2026-0310, the flaw exists in XML processing, and the vendor has assigned it the highest suggested urgency. The vulnerability is a buffer overflow, classified as CWE-787 (out-of-bounds write).
An attacker with network access to a vulnerable management web interface or dataplane interface could send specially crafted XML data to trigger the issue.
On PA-Series appliances, successful exploitation may lead to arbitrary code execution as the root user, giving an attacker complete control over the firewall operating environment. Root-level code execution on an enterprise perimeter firewall presents a serious security risk.
A threat actor could potentially alter security policies, inspect or redirect network traffic, deploy persistence mechanisms, steal configuration data, or use the compromised device as a foothold for attacks against internal systems.
Palo Alto PAN-OS Vulnerability
The issue does not require authentication or user interaction, although exploitation has been rated as high complexity. Palo Alto Networks assigned CVE-2026-0310 a CVSS-BT score of 7.2 and a CVSS-B base score of 9.2 for affected PA-Series firewalls.
The vendor noted that the practical risk is greatest for physical firewall appliances because the flaw can result in root-level remote code execution. The impact differs across Palo Alto Networks products. On vulnerable VM-Series firewalls, exploitation is limited to a denial-of-service condition rather than code execution.
A successful attack could crash or disrupt the affected virtual firewall, affecting traffic inspection and availability. Prisma Access and Cloud NGFW environments are also affected.
However, Palo Alto Networks considers the risk lower because exploitation requires an authenticated user and external network access is more restricted.
Affected PAN-OS releases include versions before 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10, depending on the release branch. Numerous maintenance builds across the 10.2, 11.1, 11.2, and 12.1 branches are also vulnerable.
Organizations should upgrade immediately to the appropriate fixed release. Palo Alto Networks recommends PAN-OS 12.2.3 or later for the 12.2 branch.
No workaround is available. However, organizations can reduce exposure by ensuring that firewall management interfaces are not reachable from untrusted networks.
Palo Alto Networks recommends restricting management access to trusted internal IP addresses and, where possible, allowing administration only through a dedicated jump box. The vendor said it discovered CVE-2026-0310 internally and, as of September 9, 2026, is not aware of malicious exploitation in the wild.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/palo-alto-pan-os-vulnerability-code-execution/