CVE-2026-0310
PAN-OS XML processing buffer overflow allows unauthenticated code execution or denial of service (CVE-2026-0310)
An unauthenticated attacker with network access to PAN-OS management or dataplane interfaces can crash VM-Series firewalls or gain root code execution on PA-Series. Fixed releases are available; no workaround exists.
What happened
An unauthenticated attacker with network access to a PAN-OS management web interface or dataplane interface can exploit a buffer overflow in XML processing. The attack requires no credentials and no user interaction, but CVSS 4.0 rates attack complexity as high. On VM-Series firewalls the result is a denial of service; on PA-Series hardware the issue can lead to arbitrary code execution with root privileges. Panorama is also impacted.
Palo Alto Networks states it is not aware of any malicious exploitation of this issue, and there has been no public disclosure. The vendor rates the risk as critical; the CVSS 4.0 score is 7.2, high.
Who is affected
Affected products include Cloud NGFW, PAN-OS, and Prisma Access. The affected PAN-OS versions are 12.2.0 to before 12.2.3, 12.1.0 to before 12.1.4-h10, 11.2.0 to before 11.2.4-h21, 11.1.0 to before 11.1.4-h36, and 10.2.0 to before 10.2.7-h37. Prisma Access is affected in 11.2.0 to before 11.2.4-h21 and 10.2.0 to before 10.2.7-h37. Cloud NGFW is listed as affected for all versions. Panorama is impacted. This is firewall and security management infrastructure, so both dataplane and management-plane exposure should be checked.
What to do now
- Apply the fixed releases named by Palo Alto Networks: PAN-OS 12.2.3; PAN-OS 12.1.10, 12.1.7-h5, 12.1.4-h10; PAN-OS 11.2.13-h2, 11.2.10-h14, 11.2.7-h20, 11.2.4-h21; PAN-OS 11.1.16-h2, 11.1.13-h12, 11.1.10-h33, 11.1.7-h10, 11.1.6-h38, 11.1.4-h36; PAN-OS 10.2.18-h10, 10.2.16-h10, 10.2.13-h24, 10.2.10-h40, 10.2.7-h37; Prisma Access 11.2.7-h20 and 10.2.10-h40.
- There are no known workarounds. Until patching is complete, follow Palo Alto Networks best practice and restrict the management interface to trusted internal IP addresses.
- For Cloud NGFW, no separate fixed version is listed in the advisory. Confirm the cloud-specific remediation status with Palo Alto Networks.
How to detect it
The vendor advisory does not provide indicators of compromise. The practical detection step is exposure review: confirm that PAN-OS management web interfaces are reachable only from trusted internal IP addresses, because the issue can be triggered over the management or dataplane interface without credentials.
Beyond the patch
This is a pre-authentication network exposure that turns a perimeter device into either a crash or a root-level compromise, depending on the appliance. Organisations that treat firewall management interfaces as internal-only still need continuous assurance that no interface has drifted into reachability; Virtual CISO Services (vCISO) provides that exposure management check. Where code execution or privilege escalation does occur, Managed Detection & Response (MDR) is the backstop for detecting the post-exploitation activity.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cloud NGFW | All | No fixed version listed yet |
| PAN-OS | 12.2.0 – < 12.2.3 12.1.0 – < 12.1.4-h10 11.2.0 – < 11.2.4-h21 11.1.0 – < 11.1.4-h36 10.2.0 – < 10.2.7-h37 | 12.2.3 12.1.10 12.1.7-h5 12.1.4-h10 11.2.13-h2 11.2.10-h14 11.2.7-h20 11.2.4-h21 11.1.16-h2 11.1.13-h12 11.1.10-h33 11.1.7-h10 11.1.6-h38 11.1.4-h36 10.2.18-h10 10.2.16-h10 10.2.13-h24 10.2.10-h40 10.2.7-h37 |
| Prisma Access | 11.2.0 – < 11.2.4-h21 10.2.0 – < 10.2.7-h37 | 11.2.7-h20 10.2.10-h40 |