CVE-2026-0310

Summary

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.

The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

Panorama is impacted by this vulnerability.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksCloud NGFWAllaffected
Palo Alto NetworksPAN-OS12.2.0 < 12.2.3affected
Palo Alto NetworksPAN-OS12.1.0 < 12.1.4-h10affected
Palo Alto NetworksPAN-OS11.2.0 < 11.2.4-h21affected
Palo Alto NetworksPAN-OS11.1.0 < 11.1.4-h36affected
Palo Alto NetworksPAN-OS10.2.0 < 10.2.7-h37affected
Palo Alto NetworksPrisma Access12.1.0 < 12.1.4-h10unaffected
Palo Alto NetworksPrisma Access11.2.0 < 11.2.4-h21affected
Palo Alto NetworksPrisma Access10.2.0 < 10.2.7-h37affected

Weaknesses

  • CWE-787: CWE-787 Out-of-bounds Write

Workarounds

No known workarounds exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References