Palo Alto Networks PAN-OS XML buffer overflow enables denial of service or root code execution

What is CVE-2026-0310?

CVE-2026-0310 is a vulnerability classified as Out-of-bounds Write, affecting Cloud NGFW (affected versions: All), PAN-OS, and Prisma Access. This vulnerability is rated High, with a CVSS score of 7.2. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431. Panorama is impacted by this vulnerability.

Affected products and scope

  • Cloud NGFW: All deployments on AWS and Azure are marked affected; no AWS or Azure deployments are marked unaffected. Palo Alto Networks states that upgrades will occur during the next scheduled maintenance cycle, with on-demand scheduling available through support.
  • PAN-OS 12.2: Versions < 12.2.3 are affected; 12.2.3 and versions the vendor marks from that point onward are unaffected.
  • PAN-OS 12.1: The branches < 12.1.4-h10, < 12.1.7-h5, and < 12.1.10 are affected; the corresponding 12.1.4-h10, 12.1.7-h5, and 12.1.10 boundaries are marked unaffected.
  • PAN-OS 11.2: The branches < 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, and < 11.2.13-h2 are affected; the corresponding boundaries are marked unaffected.
  • PAN-OS 11.1: The branches < 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, and < 11.1.16-h2 are affected; the corresponding boundaries are marked unaffected.
  • PAN-OS 10.2: The branches < 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, and < 10.2.18-h10 are affected; the corresponding boundaries are marked unaffected.
  • Prisma Access: The branches < 12.1.7-h5*, < 11.2.7-h20*, and < 10.2.10-h40* are affected. The * qualifier is used by the vendor for the managed service.
  • Panorama: The vendor confirms that Panorama is impacted, but the product-status table does not provide a separate Panorama version boundary. Check the underlying PAN-OS release and deployment status.

Technical details

The vulnerability is an out-of-bounds write in the XML processing functionality of Palo Alto Networks PAN-OS. Network requests reaching the management web or dataplane interface can place attacker-controlled data on the affected processing path, but the advisory does not disclose the parser, XML field, memory operation, or exact input format. For the described PA-Series and VM-Series path, the attacker does not need authentication or user interaction, and the advisory states that no special configuration is required to be affected. The outcome depends on the platform: VM-Series may be forced into a denial of service condition, while PA-Series may allow arbitrary code execution with root privileges. Panorama is also impacted, but the source does not provide a separate Panorama release list. The exploit primitive, payload, and precise memory conditions remain undisclosed.

Exploitability

The primary attack path is network access to the management web or dataplane interface. For PA-Series and VM-Series, the advisory describes an unauthenticated attacker and no required user interaction. Palo Alto Networks assesses the risk as lower for Cloud NGFW and Prisma Access because an authenticated user is required and external network access is restricted. The primary vendor assessment characterizes attack complexity as high, while the consequence and access conditions vary by deployment. Palo Alto Networks states that it is not aware of malicious exploitation; the supplied record does not identify a public exploit.

Technical impact

On PA-Series, the flaw can lead to arbitrary code execution with root privileges, creating the potential for deep control of the firewall and its security functions. On VM-Series, the vendor describes the outcome as denial of service rather than code execution. Panorama is impacted, so centralized management must be included in the remediation scope. Cloud NGFW and Prisma Access have authentication and network-exposure constraints that reduce exploitability according to the vendor, but those constraints do not remove the need to verify patch status. The realized impact depends on the platform, release, reachability of the interface, and whether the attacker can cause a request to reach XML processing.

Business impact

  • On PA-Series, root-level arbitrary code execution could seriously affect firewall confidentiality, configuration integrity, and availability.
  • On VM-Series, the documented outcome is denial of service, which could interrupt firewall functions or traffic flows that depend on the device.
  • Panorama is impacted, so a vulnerable centralized management deployment should be included in the review scope.
  • Cloud NGFW and Prisma Access have lower operational exposure according to the vendor because external access is restricted and authentication is required, but their upgrade status still needs verification.
  • Restricting management access to a jump box or trusted internal network reduces reachability but does not remove the vulnerability.

Remediation

  1. Upgrade PAN-OS by branch:
  • PAN-OS 12.2: For 12.2.0 through 12.2.2, upgrade to 12.2.3 or a later release explicitly covered by the vendor recommendation.
  • PAN-OS 12.1: For 12.1.8 through 12.1.9, upgrade to 12.1.10 or later; for 12.1.5 through 12.1.7-h*, upgrade to 12.1.7-h5 or 12.1.10 or later; for 12.1.2 through 12.1.4-h*, upgrade to 12.1.4-h10 or 12.1.10 or later.
  • PAN-OS 11.2: For 11.2.11 through 11.2.13-h*, upgrade to 11.2.13-h2; for 11.2.8 through 11.2.10-h*, upgrade to 11.2.10-h14; for 11.2.5 through 11.2.7-h*, upgrade to 11.2.7-h20; for 11.2.0 through 11.2.4-h*, upgrade to 11.2.4-h21. The vendor explicitly permits a later release on the applicable branch.
  • PAN-OS 11.1: For 11.1.14 through 11.1.16-h*, upgrade to 11.1.16-h2; for 11.1.11 through 11.1.13-h*, upgrade to 11.1.13-h12; for 11.1.8 through 11.1.10-h*, upgrade to 11.1.10-h33; for 11.1.7 through 11.1.7-h*, upgrade to 11.1.7-h10; for 11.1.5 through 11.1.6-h*, upgrade to 11.1.6-h38; for 11.1.0 through 11.1.4-h*, upgrade to 11.1.4-h36.
  • PAN-OS 10.2: For 10.2.17 through 10.2.18-h*, upgrade to 10.2.18-h10; for 10.2.14 through 10.2.16-h*, upgrade to 10.2.16-h10; for 10.2.11 through 10.2.13-h*, upgrade to 10.2.13-h24; for 10.2.8 through 10.2.10-h*, upgrade to 10.2.10-h40; for 10.2.0 through 10.2.7-h*, upgrade to 10.2.7-h37.
  1. Handle Prisma Access: Upgrade to 12.1.7-h5, 11.2.7-h20, or 10.2.10-h40 for the applicable branch. Palo Alto Networks states that the service will be upgraded during the next scheduled maintenance cycle; contact support or the account team for an earlier on-demand window.
  2. Handle Cloud NGFW: Work with Palo Alto Networks support to schedule an on-demand upgrade if waiting for the scheduled maintenance cycle is not acceptable.
  3. For older unsupported PAN-OS releases, upgrade to a supported release that the vendor identifies as fixed.
  4. Restrict the management interface to a jump box or trusted internal IP addresses while upgrades are pending. The vendor states that no known workaround exists, so this reduces exposure but does not replace patching.

Detection

  1. Inventory all PAN-OS devices, PA-Series and VM-Series firewalls, Panorama deployments, Cloud NGFW deployments, and Prisma Access tenants.
  2. Record the release running on each deployment and compare it with the branch-specific affected and fixed boundaries in the advisory.
  3. Verify whether the management web or dataplane interface is reachable from untrusted networks, especially where the interface can process XML requests.
  4. Check whether management access is restricted to a jump box or trusted internal IP addresses. This reduces exposure but does not demonstrate that the software is fixed.
  5. Review for unexpected restarts, loss of availability, or service disruption as a supplementary check. The available evidence does not define a specific IOC or log signature, and the absence of anomalous logs does not prove that a system is safe.
Sources (6)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard