ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

Palo Alto Networks patches unauthenticated PAN-OS XML buffer overflow CVE-2026-0310 enabling root code execution on PA-Series firewalls

What's new: Added the Canadian Centre for Cyber Security advisory AV26-905, which confirms CVE-2026-0310 is tracked as PAN-SA-2026-0012 and extends the affected-product picture to Cloud NGFW on AWS/Azure and Prisma Browser prior to 151.26.5.170, the latter tied to the separate September 2026 Chromium monthly vulnerability update rather than the PAN-OS buffer overflow. The previously noted disagreement on the…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Palo Alto Networks disclosed and fixed CVE-2026-0310 (CVSS-B 9.2), an unauthenticated out-of-bounds write in PAN-OS XML processing that lets network-adjacent attackers execute arbitrary code as root on PA-Series firewalls; VM-Series is limited to…

On September 9, 2026, Palo Alto Networks published an advisory for CVE-2026-0310, a CWE-787 out-of-bounds write in PAN-OS XML processing with a CVSS v4.0 base (CVSS-B) score of 9.2 and a CVSS-BT score of 7.2, tracked as PAN-SA-2026-0012. An unauthenticated attacker with network access to a vulnerable management or dataplane interface can send crafted XML to execute arbitrary code as root on PA-Series hardware firewalls; no special configuration is required. On VM-Series, exploitation is limited to denial-of-service, while Prisma Access and Cloud NGFW require authentication and carry reduced risk. Affected branches are PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2. Fixed releases include 12.2.3, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; sources disagree on the 12.1 fix, citing either 12.1.10 (Cyber Security News) or 12.1.4-h10 (GBHackers). No official workaround exists, though the vendor recommends restricting management interface access to trusted IPs or a dedicated jump box. The flaw was found internally by the vendor; no malicious exploitation in the wild was known as of September 9, 2026, but Palo Alto classifies remediation urgency as highest. On September 10, 2026, the Canadian Centre for Cyber Security issued advisory AV26-905, noting that as of that date multiple Palo Alto Networks products are affected; it relays the Palo Alto advisories, references CVE-2026-0310 as a PAN-OS buffer overflow via XML processing (PAN-SA-2026-0012), and lists affected products including Cloud NGFW on AWS and Azure, multiple PAN-OS versions, Prisma Access, and Prisma Browser prior to 151.26.5.170. Prisma Browser is affected by the separate September 2026 Chromium monthly vulnerability update. Administrators are advised to review vendor advisories and apply available updates.

  • CVE-2026-0310: CWE-787 out-of-bounds write in PAN-OS XML processing; CVSS v4.0 base (CVSS-B) 9.2, CVSS-BT 7.2; no authentication or special configuration required
  • Unauthenticated attacker with network access to a vulnerable management or dataplane interface can send crafted XML to execute arbitrary code as root on PA-Series appliances
  • VM-Series exploitation is limited to denial-of-service; Prisma Access and Cloud NGFW require authentication with reduced risk
  • Affected branches: PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2
  • Fixed releases: 12.2.3, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; the 12.1 fix is reported as 12.1.10 (Cyber Security News) or 12.1.4-h10 (GBHackers) - sources disagree
  • No workaround available; vendor recommends restricting management interface access to trusted IPs or a dedicated jump box
  • Flaw found internally by Palo Alto; no malicious exploitation in the wild as of September 9, 2026; remediation urgency classified as highest
  • Canadian Centre for Cyber Security advisory AV26-905 (September 10, 2026) relays the Palo Alto advisories and tracks the PAN-OS issue as PAN-SA-2026-0012

Coverage timeline

  1. · 5d ago
    Cyber Security News· 62
    Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

    Palo Alto Networks patched CVE-2026-0310, an unauthenticated XML-processing buffer overflow in PAN-OS allowing root code execution on PA-Series firewalls.

  2. · 5d ago
    GBHackers· 78
    Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

    Palo Alto Networks fixed CVE-2026-0310, a CVSS 9.2 unauthenticated PAN-OS buffer overflow enabling root code execution on PA-Series firewalls.

  3. · 5d ago
    Canadian Centre for Cyber Security· 20
    Palo Alto Networks security advisory (AV26-905)

    Canada's Cyber Centre relayed Palo Alto Networks advisories covering PAN-OS, Cloud NGFW, Prisma Access, and Prisma Browser vulnerabilities, including PAN-OS CVE-2026-0310 buffer overflow.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0310
Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls

Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven).

Do: Patch to a fixed PAN-OS release as soon as Palo Alto Networks publishes fixed versions, prioritizing PA-Series firewalls and Panorama where root code execution is possible; the advisory does not name specific fixed builds, so consult the vendor advisory for branch-specific updates. Until patching, restrict access to the management web and dataplane interfaces to trusted internal IP addresses per the vendor's management-access hardening guidance, and audit which firewalls, VM-Series instances, and Panorama servers have these interfaces reachable from untrusted networks. Monitor Palo Alto Networks advisories for updates on exploitation status and proof-of-concept releases.

7.2
  • Palo Alto Networks PAN-OS on PA-Series firewalls
  • Palo Alto Networks PAN-OS on VM-Series firewalls
  • Palo Alto Networks Panorama
largetens of thousands of exposed PAN-OS systems (public internet scans have historically shown on the order of 10,000-50,000 PAN-OS management and dataplane…