CVE-2026-0310: PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)

Published Sep 9, 2026
·
Updated

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.

The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).

Panorama is impacted by this vulnerability.

Affected Software

3 affected componentsFixes available
Palo Alto Networks PAN-OS
Palo Alto Networks PAN-OS<12.2.3, =12.2.0, <12.1.4-h10, =12.1.0, <11.2.4-h21, =11.2.0, <11.1.4-h36, =11.1.0, <10.2.7-h37, =10.2.0
12.2.312.1.1012.1.7-h512.1.4-h1011.2.13-h211.2.10-h1411.2.7-h2011.2.4-h2111.1.16-h211.1.13-h1211.1.10-h3311.1.7-h1011.1.6-h3811.1.4-h3610.2.18-h1010.2.16-h1010.2.13-h2410.2.10-h4010.2.7-h37
Palo Alto Networks Prisma Access=11.2.0, =10.2.0
11.2.7-h2010.2.10-h40

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 12.2.3Fixed in 12.1.10Fixed in 12.1.7-h5Fixed in 12.1.4-h10Fixed in 11.2.13-h2Fixed in 11.2.10-h14Fixed in 11.2.7-h20Fixed in 11.2.4-h21Fixed in 11.1.16-h2Fixed in 11.1.13-h12Fixed in 11.1.10-h33Fixed in 11.1.7-h10Fixed in 11.1.6-h38Fixed in 11.1.4-h36Fixed in 10.2.18-h10Fixed in 10.2.16-h10Fixed in 10.2.13-h24Fixed in 10.2.10-h40Fixed in 10.2.7-h37
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 11.2.7-h20Fixed in 10.2.10-h40
  3. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.7-h37
  4. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.18
  5. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.13-h24
  6. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.16-h10
  7. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.10-h40
  8. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.4-h36
  9. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.16
  10. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.13-h12
  11. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.6-h38
  12. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.7-h10
  13. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.10-h33
  14. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.4-h21
  15. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.7-h20
  16. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.10-h14
  17. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.4-h10
  18. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.10
  19. Upgrade

    Upgrade PAN-OS to a version that resolves this vulnerability.

    Fixed in 12.1.7-h5
  20. Upgrade

    Upgrade Prisma Access 10.2 to a version that resolves this vulnerability.

    Fixed in 10.2.10-h40
  21. Upgrade

    Upgrade Prisma Access 11.2 to a version that resolves this vulnerability.

    Fixed in 11.2.7-h20
  22. Upgrade

    Upgrade Prisma Access 12.1 to a version that resolves this vulnerability.

    Fixed in 12.1.7-h5
  23. Compensating control

    Minimize the security risk by restricting the management interface to only trusted internal IP addresses, per Palo Alto Networks recommended best-practice deployment guidelines.

Event History

Sep 9, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which systems and interfaces are exposed to this issue?

VM-Series firewalls, PA-Series firewalls, and Panorama are impacted. Exploitation requires network access to either the management web interface or the dataplane interface.

2

What can an unauthenticated attacker achieve?

An unauthenticated attacker can cause a denial-of-service condition on VM-Series firewalls. On PA-Series firewalls, the attacker may be able to execute arbitrary code with root privileges.

3

Does restricting management-interface access reduce exposure?

Yes. The stated risk is minimized when the management interface is limited to trusted internal IP addresses in accordance with recommended deployment practices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203