ZeroHour
Story · 1 source · 1 articlefirst updated ()

Palo Alto Networks Patches CVE-2026-0310: Unauthenticated PAN-OS XML Buffer Overflow Enables Root Code Execution on PA-Series Firewalls

What's new: First merged summary for this story. Initial vendor-side coverage (September 9, 2026 advisory; reported September 10, 2026) detailed CVE-2026-0310 severity, product-specific impact, affected branches, and fixed releases. Subsequently, Canada's Cyber Centre issued advisory AV26-905 on September 10, 2026, corroborating CVE-2026-0310 via PAN-SA-2026-0012 and adding context on Cloud NGFW (AWS/Azure),…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Palo Alto Networks fixed CVE-2026-0310 (CVSS v4.0 9.2, PAN-SA-2026-0012), an unauthenticated out-of-bounds write in PAN-OS XML processing that lets attackers execute arbitrary code as root on PA-Series firewalls; fixed releases exist for PAN-OS 10.2 through…

On September 9, 2026, Palo Alto Networks published an advisory for CVE-2026-0310, a CWE-787 out-of-bounds write in PAN-OS XML processing with a CVSS v4.0 base score of 9.2, affecting the management and dataplane interfaces. Unauthenticated attackers can execute arbitrary code as root on PA-Series hardware firewalls, while VM-Series faces denial-of-service impact and Prisma Access and Cloud NGFW have reduced, authenticated exposure. Affected branches are PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2, with fixed maintenance releases including 12.2.3, 12.1.4-h10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10. No workaround is available, though the vendor recommends restricting management access to trusted IPs or a dedicated jump box. Palo Alto is not aware of malicious exploitation but rates remediation urgency as highest. On September 10, 2026, the Canadian Centre for Cyber Security relayed the issue in advisory AV26-905, which cites CVE-2026-0310 as a PAN-OS buffer overflow via XML processing tracked in PAN-SA-2026-0012 and also covers Cloud NGFW on AWS and Azure, Prisma Access, and Prisma Browser prior to 151.26.5.170; Prisma Browser is additionally affected by the September 2026 Chromium monthly vulnerability update. Both sources urge administrators to apply available updates.

  • CVE-2026-0310 is a CWE-787 out-of-bounds write in PAN-OS XML processing, CVSS v4.0 base score 9.2, requiring no authentication or special configuration; it is tracked in vendor advisory PAN-SA-2026-0012.
  • Impact varies by product: PA-Series hardware firewalls face unauthenticated root-level arbitrary code execution; VM-Series is limited to denial of service; Prisma Access and Cloud NGFW have reduced, authenticated exposure.
  • Affected PAN-OS branches: 10.2, 11.1, 11.2, 12.1, and 12.2, with fixed releases including 12.2.3, 12.1.4-h10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10.
  • Vendor advisory published September 9, 2026; no workaround exists, but Palo Alto recommends restricting management access to trusted IPs or a dedicated jump box.
  • Palo Alto reports no known malicious exploitation as of the advisory but classifies remediation urgency as highest.
  • Canada's Cyber Centre advisory AV26-905 (September 10, 2026) also lists Cloud NGFW on AWS and Azure, Prisma Access, and Prisma Browser prior to 151.26.5.170; Prisma Browser is additionally affected by the September 2026 Chromium monthly…
  • Both sources direct administrators to review vendor advisories and apply available updates.

Coverage timeline

  1. · 7d ago
    GBHackers· 78
    Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

    Palo Alto Networks fixed CVE-2026-0310, a CVSS 9.2 unauthenticated PAN-OS buffer overflow enabling root code execution on PA-Series firewalls.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0310
Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls

Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven).

Do: Patch to a fixed PAN-OS release as soon as Palo Alto Networks publishes fixed versions, prioritizing PA-Series firewalls and Panorama where root code execution is possible; the advisory does not name specific fixed builds, so consult the vendor advisory for branch-specific updates. Until patching, restrict access to the management web and dataplane interfaces to trusted internal IP addresses per the vendor's management-access hardening guidance, and audit which firewalls, VM-Series instances, and Panorama servers have these interfaces reachable from untrusted networks. Monitor Palo Alto Networks advisories for updates on exploitation status and proof-of-concept releases.

7.2
  • Palo Alto Networks PAN-OS on PA-Series firewalls
  • Palo Alto Networks PAN-OS on VM-Series firewalls
  • Palo Alto Networks Panorama
largetens of thousands of exposed PAN-OS systems (public internet scans have historically shown on the order of 10,000-50,000 PAN-OS management and dataplane…