Security Advisory Desk
highQCS priority 94/100Palo Alto Networks

CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)

A serious security flaw was found in Palo Alto Networks' PAN-OS software, affecting various firewall products including PA-Series hardware, VM-Series virtual firewalls, and Panorama management. This flaw involves a buffer overflow during XML data processing, which could allow attackers to disrupt services or, on some models, run harmful code with full control without needing any login credentials. Palo Alto Networks has released software updates to fix this issue, and customers are advised to upgrade to these fixed versions promptly for protection.

Published 9/9/2026, 4:00:00 pmVerified 16/9/2026, 3:21:53 amRevision 1
Palo Alto Networks high network security advisory visual

In plain language

What this advisory means

A serious security flaw was found in Palo Alto Networks' PAN-OS software, affecting various firewall products including PA-Series hardware, VM-Series virtual firewalls, and Panorama management. This flaw involves a buffer overflow during XML data processing, which could allow attackers to disrupt services or, on some models, run harmful code with full control without needing any login credentials. Palo Alto Networks has released software updates to fix this issue, and customers are advised to upgrade to these fixed versions promptly for protection.

Technical explanation

How the issue affects the environment

The vulnerability (CVE-2026-0310) stems from a buffer overflow in the XML processing component of PAN-OS, which can be triggered via network access to management web or dataplane interfaces. For PA-Series hardware firewalls, exploitation may lead to arbitrary code execution with root privileges, posing high confidentiality, integrity, and availability risks without requiring authentication. VM-Series firewalls are affected primarily with a denial of service (DoS) risk. Panorama management systems are also impacted. The flaw involves an out-of-bounds write (CWE-787) due to inadequate bounds checking in XML handling, allowing potentially malicious data to overwrite memory. Palo Alto Networks implemented fixes in multiple PAN-OS versions starting with 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10, among others. No known workarounds exist; access restriction to the management interface can reduce risk but not eliminate it.

Operational impact

Why teams should care

If exploited, this vulnerability could lead to service disruptions due to denial of service attacks or full compromise of firewall systems on PA-Series hardware, allowing attackers to execute arbitrary code with root access. This compromises the confidentiality, integrity, and availability of enterprise network security infrastructure, potentially leading to unauthorized data access, network breaches, and downtime. Organizations must urgently upgrade affected systems to prevent potential malicious activities that can severely impact network operations and security posture.

Immediate action

Administrators should upgrade affected Palo Alto Networks devices to the fixed PAN-OS versions listed by Palo Alto Networks as soon as possible. For Prisma Access and Cloud NGFW users, Palo Alto Networks will perform scheduled upgrades but support can provide on-demand upgrades if required. There are no known workarounds that fully mitigate this vulnerability. Network access to management interfaces should be restricted to trusted jump boxes to reduce risk, but upgrading is the definitive remediation step.

Affected and fixed releases

Affected versionsPAN-OS 12.2.0 up to 12.2.3, PAN-OS 12.1.0 up to 12.1.10, PAN-OS 12.1.4 up to 12.1.4-h10, PAN-OS 12.1.7 up to 12.1.7-h5, PAN-OS 11.2.4 up to 11.2.4-h21, PAN-OS 11.2.7 up to 11.2.7-h20, PAN-OS 11.2.10 up to 11.2.10-h14, PAN-OS 11.2.13 up to 11.2.13-h2, PAN-OS 11.1.4 up to 11.1.4-h36, PAN-OS 11.1.6 up to 11.1.6-h38, PAN-OS 11.1.7 up to 11.1.7-h10, PAN-OS 11.1.10 up to 11.1.10-h33, PAN-OS 11.1.13 up to 11.1.13-h12, PAN-OS 11.1.16 up to 11.1.16-h2, PAN-OS 10.2.7 up to 10.2.7-h37, PAN-OS 10.2.10 up to 10.2.10-h40, PAN-OS 10.2.13 up to 10.2.13-h24, PAN-OS 10.2.16 up to 10.2.16-h10, PAN-OS 10.2.18 up to 10.2.18-h10
Fixed versionsPAN-OS 12.2.3 and later, PAN-OS 12.1.10 and later, PAN-OS 12.1.4-h10 and later, PAN-OS 12.1.7-h5 and later, PAN-OS 11.2.4-h21 and later, PAN-OS 11.2.7-h20 and later, PAN-OS 11.2.10-h14 and later, PAN-OS 11.2.13-h2 and later, PAN-OS 11.1.4-h36 and later, PAN-OS 11.1.6-h38 and later, PAN-OS 11.1.7-h10 and later, PAN-OS 11.1.10-h33 and later, PAN-OS 11.1.13-h12 and later, PAN-OS 11.1.16-h2 and later, PAN-OS 10.2.7-h37 and later, PAN-OS 10.2.10-h40 and later, PAN-OS 10.2.13-h24 and later, PAN-OS 10.2.16-h10 and later, PAN-OS 10.2.18-h10 and later

Temporary risk reduction

No effective workaround exists to fully mitigate this vulnerability. Restricting network access to the management interface via a trusted jump host can reduce exposure risk but does not eliminate the vulnerability. Users should prioritize applying software updates to address this issue.

Evidence and validation checklist

  • Official Palo Alto Networks Security Advisory published on 2026-09-09
  • Detailed description of CVE-2026-0310 including technical impact
  • Listing of affected and fixed PAN-OS versions
  • Severity rating as HIGH with CVSS score 7.2
  • No reported active exploitation
  • No known workaround exists
  • Recommended upgrade path and remediation instructions

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source