Vulnerability
Published 2026-09-09
Verified 2026-09-19

PAN-OS CVE-2026-0310 XML buffer overflow (vendor sev 7.2); DoS on VM-Series / root RCE on PA-Series

Palo Alto Networks security advisory CVE-2026-0310 (published 9 September 2026): buffer overflow in PAN-OS XML processing lets an unauthenticated network attacker with access to the management web or dataplane interface cause DoS on VM-Series firewalls or execute arbitrary code as root on PA-Series. Vendor severity 7.2 HIGH; urgency HIGHEST; exploit maturity UNREPORTED. Panorama is impacted. Risk is reduced when management is restricted to trusted internal IPs per Palo Alto best practice. Fixed builds include PAN-OS 12.2.3; 12.1.4-h10 / 12.1.7-h5 / 12.1.10; 11.2.4-h21 / 11.2.7-h20 / 11.2.10-h14 / 11.2.13-h2; 11.1.4-h36 / 11.1.6-h38 / 11.1.7-h10 / 11.1.10-h33 / 11.1.13-h12 / 11.1.16-h2; 10.2.7-h37 / 10.2.10-h40 / 10.2.13-h24 / 10.2.16-h10 / 10.2.18-h10 (confirm against the live advisory for your branch). Prisma Access / Cloud NGFW called medium severity on the same advisory and are scheduled for maintenance upgrades. Primary: Palo Alto Networks advisory.

Product
Palo Alto Networks PAN-OS / Panorama (PA-Series, VM-Series); Prisma Access / Cloud NGFW (medium on advisory)
Versions
See vendor table: fixed at 12.2.3; 12.1.4-h10/12.1.7-h5/12.1.10; 11.2.4-h21/11.2.7-h20/11.2.10-h14/11.2.13-h2; 11.1.4-h36/11.1.6-h38/11.1.7-h10/11.1.10-h33/11.1.13-h12/11.1.16-h2; 10.2.7-h37/10.2.10-h40/10.2.13-h24/10.2.16-h10/10.2.18-h10
CVSS
7.2 (vendor HIGH)
Exploited in Australia?
unknown
Patch to
Upgrade PAN-OS/Panorama to a fixed build on the advisory table; restrict management to trusted IPs; Prisma Access/Cloud NGFW via scheduled or on-demand upgrade

Primary: Palo Alto Networks — CVE-2026-0310 (9 Sep 2026) · Vendor: Palo Alto Networks (vendor) · CVE: CVE-2026-0310

vulnerabilities network