Skip to content

Release roundup

Palo Alto Networks week 37 2026: PAN-OS XML buffer overflow leads nine fixes

High 7.2 Vendor: Palo Alto Networks 9 CVEs in scope Published

Palo Alto Networks published 9 CVEs for 7–13 September 2026: 1 high, 5 medium, 3 low. None is in CISA KEV or reported exploited. CVE-2026-0310, an unauthenticated PAN-OS XML buffer overflow, can cause DoS or root code execution. Patch PAN-OS/Prisma Access first, then agents and Checkov.

The release at a glance

Palo Alto Networks published nine CVEs for the week of 7–13 September 2026. The release spans Cloud NGFW (three), Prisma Access Agent (two), Checkov by Prisma Cloud (two), GlobalProtect App (one) and Cortex XDR Broker VM (one). By CVSS severity there is one high, five medium and three low; no CVE is listed in CISA KEV and the vendor states it is not aware of malicious exploitation.

CVE-2026-0310 is the most significant issue: a buffer overflow in PAN-OS XML processing. An unauthenticated attacker with network access to the management web or dataplane interface can cause a denial of service on VM-Series or execute arbitrary code as root on PA-Series. Panorama is also affected. The vendor rates it critical, while its CVSS 4.0 score is 7.2 high.

What matters most

PAN-OS, Cloud NGFW and Prisma Access. CVE-2026-0310 should be examined first. An unauthenticated attacker with network access to the PAN-OS management web or dataplane interface can trigger an XML processing buffer overflow, causing denial of service on VM-Series and potential root-level code execution on PA-Series. Panorama is also affected, and Cloud NGFW and Prisma Access are in scope. Fixed versions include PAN-OS 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 and 10.2.18-h10, plus earlier branch hotfixes; Prisma Access fixes include 11.2.7-h20 and 10.2.10-h40. This CVE has a separate advisory page on this site.

Two further PAN-OS issues are internal. CVE-2026-0309 is command injection in the CLI when a Luna HSM is configured; an authenticated administrator can run commands as root. Cloud NGFW, Panorama and Prisma Access are not affected. CVE-2026-0308 is stored cross-site scripting in the web interface by a malicious authenticated administrator on PA-Series, VM-Series and Panorama; fixes include PAN-OS 12.1.10, 11.2.13-h2 and 11.1.16-h2.

GlobalProtect App. CVE-2026-0307 allows a local user to escalate to SYSTEM on Windows or root on macOS and Linux, enabling arbitrary command execution with administrative privileges. iOS, Android and ChromeOS are not affected. Fixes are 6.3.3-h15, 6.2.8-h14 and 6.0.15.

Prisma Access Agent. CVE-2026-0306 lets a local Windows user bypass EndPoint DLP enforcement and exfiltrate sensitive data; the fix is 26.2. CVE-2026-0305 on Linux lets a local user access sensitive configuration data and credentials; the fix is 26.3.

Cortex XDR Broker VM. CVE-2026-0304 allows an authenticated low-privileged user with man-in-the-middle access to execute code as root; it is fixed in 32.0.52.

Checkov by Prisma Cloud. CVE-2026-0303 allows arbitrary code execution when Checkov scans a directory containing an attacker-controlled configuration file; the fix is 3.2.532. CVE-2026-0302 allows local OS command injection in processes running Checkov; the fix is 3.2.502.

Patch in this order

  1. Start with CVE-2026-0310 on any PAN-OS management or dataplane interface reachable from untrusted networks. Apply fixed versions such as PAN-OS 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 or 10.2.18-h10; for Prisma Access use 11.2.7-h20 or 10.2.10-h40. Cloud NGFW is also listed as affected.
  2. Update GlobalProtect App to 6.3.3-h15, 6.2.8-h14 or 6.0.15 according to your branch. Update Prisma Access Agent to 26.2 on Windows and 26.3 on Linux. Update Cortex XDR Broker VM to 32.0.52.
  3. Update Checkov by Prisma Cloud to 3.2.532 or later for CVE-2026-0303 and 3.2.502 or later for CVE-2026-0302, especially where scans run against untrusted directories or code.
  4. Apply the relevant PAN-OS fixes for CVE-2026-0309 only if your devices use a Luna HSM and CLI access is shared. Patch CVE-2026-0308 during the next scheduled web interface update.

Beyond the patch

Releases like this become routine once the exposure questions are already answered. Virtual CISO Services can ensure PAN-OS management interfaces are restricted to trusted internal addresses, directly reducing the risk from CVE-2026-0310, and Implementation & Assessment Services can verify that the agent, Broker VM and Checkov updates are tested and applied as part of your normal patch cycle.

Every CVE in this release

CVEProductSeverity
CVE-2026-0310Cloud NGFWHigh 7.2Advisory →
CVE-2026-0307GlobalProtect AppMedium 5.9
CVE-2026-0306Prisma Access AgentMedium 5.8
CVE-2026-0304Cortex XDR Broker VMMedium 4.8
CVE-2026-0305Prisma Access AgentMedium 4.3
CVE-2026-0309Cloud NGFWMedium 4.0
CVE-2026-0303Checkov by Prisma CloudLow 2.4
CVE-2026-0302Checkov by Prisma CloudLow 1.1
CVE-2026-0308Cloud NGFWLow 1.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.