CVE Tools

CVE-2026-0310

PAN-OS: Buffer Overflow Vulnerability via XML Processing

Published: Sep 10, 2026Updated: Sep 11, 2026 Sources: CVE List NVDCWE-787

Description

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama is impacted by this vulnerability.

In plain language

AI Act now

This flaw can let an outsider crash or take control of an unpatched PAN-OS, Prisma Access, or Cloud NGFW firewall, so affected small businesses should act urgently.

Executive summary

Unauthenticated network-reachable XML-processing buffer overflow (CWE-787) permits DoS on VM-Series systems or root-level arbitrary command execution on PA-Series firewalls.

If affected, business impact
Full firewall takeoverNetwork outageTraffic interceptionBusiness-service disruptionRansomware risk

What to do now

  1. Check whether you run PAN-OS, Prisma Access, or Cloud NGFW and record the installed software version.
  2. Upgrade PAN-OS to 12.2.3, 12.1.4-h10, 11.2.4-h21, 11.1.4-h36, or 10.2.7-h37, as appropriate for your release branch.
  3. Upgrade Prisma Access to 12.1.0, 11.2.4-h21, or 10.2.7-h37, as appropriate for your release branch.
  4. Ask Palo Alto Networks support to schedule an on-demand Cloud NGFW software upgrade.
  5. Until upgrades are complete, limit management-interface access to trusted internal IP addresses and restrict unnecessary network access to affected interfaces.
Usually a quick update

Weaknesses

Affected Products

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available
Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-0310 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store