https://reddit.com/r/cybersecurity/comments/1ur0guw/psa_panos_authenticated_command_injection_in_the/: PSA: PAN-OS authenticated command injection in the CLI (CVE-2026-0286) - patches out for 12.1, 11.2, 11.1, 10.2
Published Jul 8, 2026
·Updated
Affected Software
1 affected component
Palo Alto Networks PAN-OS<12.1.8, =11.2.13, =11.1.16, =10.2.18-h8
Frequently Asked Questions
1
What is the severity of CVE-2026-0286?
CVE-2026-0286 is a command injection vulnerability classified with moderate severity due to the requirement for authenticated access.
2
How do I fix CVE-2026-0286?
To fix CVE-2026-0286, apply the patches available for PAN-OS versions 12.1, 11.2, 11.1, and 10.2.
3
What are the implications of CVE-2026-0286?
CVE-2026-0286 allows an authenticated attacker with CLI access to execute arbitrary commands on the underlying system, which can lead to compromise.
4
What versions of PAN-OS are affected by CVE-2026-0286?
CVE-2026-0286 affects several PAN-OS versions, specifically 12.1, 11.2, 11.1, and 10.2.
5
Is CVE-2026-0286 an unauthenticated vulnerability?
No, CVE-2026-0286 is an authenticated command injection vulnerability requiring admin or CLI access to exploit.