https://reddit.com/r/sysadmin/comments/1ur0j26/psa_panos_authenticated_command_injection_in_the/: PSA: PAN-OS authenticated command injection in the CLI (CVE-2026-0286) - patches out for 12.1, 11.2, 11.1, 10.2
Published Jul 8, 2026
·Updated
Affected Software
1 affected component
Palo Alto Networks PAN-OS<12.1.8, =11.2.13, =11.1.16, =10.2.18-h8
Frequently Asked Questions
1
What is the severity of CVE-2026-0286?
CVE-2026-0286 is a command injection vulnerability classified with lower urgency than unauthenticated remote code execution, requiring authenticated access to exploit.
2
How do I fix CVE-2026-0286?
To fix CVE-2026-0286, update your PAN-OS to the patched versions 12.1, 11.2, 11.1, or 10.2 as advised by Palo Alto Networks.
3
Who is affected by CVE-2026-0286?
Any organization or individual using Palo Alto Networks PAN-OS with admin/CLI access is potentially affected by CVE-2026-0286.
4
What is the impact of exploiting CVE-2026-0286?
Exploiting CVE-2026-0286 allows an attacker with CLI access to execute arbitrary commands on the underlying system.
5
When was CVE-2026-0286 published?
CVE-2026-0286 was published on July 8, 2026.