ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 3 sources: “Palo Alto Networks patches unauthenticated PAN-OS XML buffer overflow CVE-2026-0310 enabling root code execution on PA-Series firewalls” — merged summary and timeline →

Palo Alto Networks security advisory (AV26-905)

lowAdvisoryimportance 20CVE-2026-0310
AI summary · glm-5.3-flash

Canada's Cyber Centre relayed Palo Alto Networks advisories covering PAN-OS, Cloud NGFW, Prisma Access, and Prisma Browser vulnerabilities, including PAN-OS CVE-2026-0310 buffer overflow.

The Canadian Centre for Cyber Security issued advisory AV26-905, noting that as of September 10, 2026, multiple Palo Alto Networks products are affected by vulnerabilities. Affected products include Cloud NGFW on AWS and Azure, multiple PAN-OS versions, Prisma Access, and Prisma Browser prior to 151.26.5.170. The advisory references CVE-2026-0310, a PAN-OS buffer overflow via XML processing (PAN-SA-2026-0012), and the September 2026 Chromium monthly vulnerability update. Administrators are encouraged to review the vendor links and apply available updates.

  • Advisory AV26-905 covers Cloud NGFW (AWS/Azure), PAN-OS, Prisma Access, and Prisma Browser before 151.26.5.170.
  • CVE-2026-0310 is a PAN-OS buffer overflow via XML processing, tracked in PAN-SA-2026-0012.
  • Prisma Browser is also affected by the September 2026 Chromium monthly vulnerability update.
  • Users and administrators are advised to review vendor advisories and apply necessary updates.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0310
Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls

Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven).

Do: Patch to a fixed PAN-OS release as soon as Palo Alto Networks publishes fixed versions, prioritizing PA-Series firewalls and Panorama where root code execution is possible; the advisory does not name specific fixed builds, so consult the vendor advisory for branch-specific updates. Until patching, restrict access to the management web and dataplane interfaces to trusted internal IP addresses per the vendor's management-access hardening guidance, and audit which firewalls, VM-Series instances, and Panorama servers have these interfaces reachable from untrusted networks. Monitor Palo Alto Networks advisories for updates on exploitation status and proof-of-concept releases.

7.2
  • Palo Alto Networks PAN-OS on PA-Series firewalls
  • Palo Alto Networks PAN-OS on VM-Series firewalls
  • Palo Alto Networks Panorama
largetens of thousands of exposed PAN-OS systems (public internet scans have historically shown on the order of 10,000-50,000 PAN-OS management and dataplane…
Full article85 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-905
Date: September 10, 2026

As of September 10, 2026, Palo Alto Networks is affected by vulnerabilities in the following products:

  • Cloud NGFW
    • All on AWS*, All on Azure*
  • PAN-OS
    • Multiple versions
  • Prisma Access
    • Multiple versions
  • Prisma Browser
    • Prior to 151.26.5.170

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-905