CVE-2026-0310
PAN-OS: Buffer Overflow Vulnerability via XML Processing
Description
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama is impacted by this vulnerability.
In plain language
AI Act nowThis flaw can let an outsider crash or take control of an unpatched PAN-OS, Prisma Access, or Cloud NGFW firewall, so affected small businesses should act urgently.
Unauthenticated network-reachable XML-processing buffer overflow (CWE-787) permits DoS on VM-Series systems or root-level arbitrary command execution on PA-Series firewalls.
What to do now
- Check whether you run PAN-OS, Prisma Access, or Cloud NGFW and record the installed software version.
- Upgrade PAN-OS to 12.2.3, 12.1.4-h10, 11.2.4-h21, 11.1.4-h36, or 10.2.7-h37, as appropriate for your release branch.
- Upgrade Prisma Access to 12.1.0, 11.2.4-h21, or 10.2.7-h37, as appropriate for your release branch.
- Ask Palo Alto Networks support to schedule an on-demand Cloud NGFW software upgrade.
- Until upgrades are complete, limit management-interface access to trusted internal IP addresses and restrict unnecessary network access to affected interfaces.
Weaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-0310 and every CVE in our database. Create a free account — no credit card required.
Create Free Account