Release roundup
Palo Alto Networks week 37 2026: PAN-OS XML buffer overflow leads nine fixes
Palo Alto Networks published 9 CVEs for 7–13 September 2026: 1 high, 5 medium, 3 low. None is in CISA KEV or reported exploited. CVE-2026-0310, an unauthenticated PAN-OS XML buffer overflow, can cause DoS or root code execution. Patch PAN-OS/Prisma Access first, then agents and Checkov.
The release at a glance
Palo Alto Networks published nine CVEs for the week of 7–13 September 2026. The release spans Cloud NGFW (three), Prisma Access Agent (two), Checkov by Prisma Cloud (two), GlobalProtect App (one) and Cortex XDR Broker VM (one). By CVSS severity there is one high, five medium and three low; no CVE is listed in CISA KEV and the vendor states it is not aware of malicious exploitation.
CVE-2026-0310 is the most significant issue: a buffer overflow in PAN-OS XML processing. An unauthenticated attacker with network access to the management web or dataplane interface can cause a denial of service on VM-Series or execute arbitrary code as root on PA-Series. Panorama is also affected. The vendor rates it critical, while its CVSS 4.0 score is 7.2 high.
What matters most
PAN-OS, Cloud NGFW and Prisma Access. CVE-2026-0310 should be examined first. An unauthenticated attacker with network access to the PAN-OS management web or dataplane interface can trigger an XML processing buffer overflow, causing denial of service on VM-Series and potential root-level code execution on PA-Series. Panorama is also affected, and Cloud NGFW and Prisma Access are in scope. Fixed versions include PAN-OS 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 and 10.2.18-h10, plus earlier branch hotfixes; Prisma Access fixes include 11.2.7-h20 and 10.2.10-h40. This CVE has a separate advisory page on this site.
Two further PAN-OS issues are internal. CVE-2026-0309 is command injection in the CLI when a Luna HSM is configured; an authenticated administrator can run commands as root. Cloud NGFW, Panorama and Prisma Access are not affected. CVE-2026-0308 is stored cross-site scripting in the web interface by a malicious authenticated administrator on PA-Series, VM-Series and Panorama; fixes include PAN-OS 12.1.10, 11.2.13-h2 and 11.1.16-h2.
GlobalProtect App. CVE-2026-0307 allows a local user to escalate to SYSTEM on Windows or root on macOS and Linux, enabling arbitrary command execution with administrative privileges. iOS, Android and ChromeOS are not affected. Fixes are 6.3.3-h15, 6.2.8-h14 and 6.0.15.
Prisma Access Agent. CVE-2026-0306 lets a local Windows user bypass EndPoint DLP enforcement and exfiltrate sensitive data; the fix is 26.2. CVE-2026-0305 on Linux lets a local user access sensitive configuration data and credentials; the fix is 26.3.
Cortex XDR Broker VM. CVE-2026-0304 allows an authenticated low-privileged user with man-in-the-middle access to execute code as root; it is fixed in 32.0.52.
Checkov by Prisma Cloud. CVE-2026-0303 allows arbitrary code execution when Checkov scans a directory containing an attacker-controlled configuration file; the fix is 3.2.532. CVE-2026-0302 allows local OS command injection in processes running Checkov; the fix is 3.2.502.
Patch in this order
- Start with CVE-2026-0310 on any PAN-OS management or dataplane interface reachable from untrusted networks. Apply fixed versions such as PAN-OS 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 or 10.2.18-h10; for Prisma Access use 11.2.7-h20 or 10.2.10-h40. Cloud NGFW is also listed as affected.
- Update GlobalProtect App to 6.3.3-h15, 6.2.8-h14 or 6.0.15 according to your branch. Update Prisma Access Agent to 26.2 on Windows and 26.3 on Linux. Update Cortex XDR Broker VM to 32.0.52.
- Update Checkov by Prisma Cloud to 3.2.532 or later for CVE-2026-0303 and 3.2.502 or later for CVE-2026-0302, especially where scans run against untrusted directories or code.
- Apply the relevant PAN-OS fixes for CVE-2026-0309 only if your devices use a Luna HSM and CLI access is shared. Patch CVE-2026-0308 during the next scheduled web interface update.
Beyond the patch
Releases like this become routine once the exposure questions are already answered. Virtual CISO Services can ensure PAN-OS management interfaces are restricted to trusted internal addresses, directly reducing the risk from CVE-2026-0310, and Implementation & Assessment Services can verify that the agent, Broker VM and Checkov updates are tested and applied as part of your normal patch cycle.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-0310 | Cloud NGFW | High 7.2 | Advisory → |
| CVE-2026-0307 | GlobalProtect App | Medium 5.9 | |
| CVE-2026-0306 | Prisma Access Agent | Medium 5.8 | |
| CVE-2026-0304 | Cortex XDR Broker VM | Medium 4.8 | |
| CVE-2026-0305 | Prisma Access Agent | Medium 4.3 | |
| CVE-2026-0309 | Cloud NGFW | Medium 4.0 | |
| CVE-2026-0303 | Checkov by Prisma Cloud | Low 2.4 | |
| CVE-2026-0302 | Checkov by Prisma Cloud | Low 1.1 | |
| CVE-2026-0308 | Cloud NGFW | Low 1.1 |
References
Vendor advisory
- PAN-OS: Buffer Overflow Vulnerability via XML Processing
- GlobalProtect App: Local Privilege Escalation Vulnerabilities
- Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
- Cortex XDR Broker VM: Privilege Escalation Vulnerability
- Prisma Access Agent: Information Disclosure Vulnerability on Linux
- PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
- Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
- Checkov by Prisma Cloud: OS Command Injection Vulnerability
CVE
- CVE-2026-0310 — cve.org
- CVE-2026-0310 — NVD
- CVE-2026-0307 — cve.org
- CVE-2026-0307 — NVD
- CVE-2026-0306 — cve.org
- CVE-2026-0306 — NVD
- CVE-2026-0304 — cve.org
- CVE-2026-0304 — NVD
- CVE-2026-0305 — cve.org
- CVE-2026-0305 — NVD
- CVE-2026-0309 — cve.org
- CVE-2026-0309 — NVD
- CVE-2026-0303 — cve.org
- CVE-2026-0303 — NVD
- CVE-2026-0302 — cve.org
- CVE-2026-0302 — NVD
- CVE-2026-0308 — cve.org
- CVE-2026-0308 — NVD