CVE-2026-0310: PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.
The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
Panorama is impacted by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.2.3Fixed in 12.1.10Fixed in 12.1.7-h5Fixed in 12.1.4-h10Fixed in 11.2.13-h2Fixed in 11.2.10-h14Fixed in 11.2.7-h20Fixed in 11.2.4-h21Fixed in 11.1.16-h2Fixed in 11.1.13-h12Fixed in 11.1.10-h33Fixed in 11.1.7-h10Fixed in 11.1.6-h38Fixed in 11.1.4-h36Fixed in 10.2.18-h10Fixed in 10.2.16-h10Fixed in 10.2.13-h24Fixed in 10.2.10-h40Fixed in 10.2.7-h37 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h20Fixed in 10.2.10-h40 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.7-h37 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h24 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.16-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h40 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h36 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.13-h12 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.6-h38 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.7-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.10-h33 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h21 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.7-h20 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.10-h14 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.4-h10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.10 - Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.7-h5 - Upgrade
Upgrade
Prisma Access 10.2to a version that resolves this vulnerability.Fixed in 10.2.10-h40 - Upgrade
Upgrade
Prisma Access 11.2to a version that resolves this vulnerability.Fixed in 11.2.7-h20 - Upgrade
Upgrade
Prisma Access 12.1to a version that resolves this vulnerability.Fixed in 12.1.7-h5 - Compensating control
Minimize the security risk by restricting the management interface to only trusted internal IP addresses, per Palo Alto Networks recommended best-practice deployment guidelines.
Event History
Frequently Asked Questions
Which systems and interfaces are exposed to this issue?
VM-Series firewalls, PA-Series firewalls, and Panorama are impacted. Exploitation requires network access to either the management web interface or the dataplane interface.
What can an unauthenticated attacker achieve?
An unauthenticated attacker can cause a denial-of-service condition on VM-Series firewalls. On PA-Series firewalls, the attacker may be able to execute arbitrary code with root privileges.
Does restricting management-interface access reduce exposure?
Yes. The stated risk is minimized when the management interface is limited to trusted internal IP addresses in accordance with recommended deployment practices.