Critical Palo Alto PAN-OS CVE-2024-3400 Allows Root Command Injection
Key Takeaways Palo Alto Networks has released patches for three vulnerabilities affecting its PAN-OS, including a critical command injection flaw. The most severe vulnerability, CVE-2026-0273, allows...
Key Takeaways
- Palo Alto Networks has released patches for three vulnerabilities affecting its PAN-OS, including a critical command injection flaw.
- The most severe vulnerability, CVE-2026-0273, allows authenticated administrators to execute arbitrary commands with root privileges.
- Affected products include PA-Series and VM-Series firewalls, along with Panorama appliances running specific versions of PAN-OS 12.1, 11.2, 11.1, and 10.2.
- While no active exploitation has been observed, immediate patching is crucial, especially where management interfaces or tunnel endpoints are accessible from less trusted networks.
Palo Alto Networks has issued an urgent advisory regarding a critical command injection vulnerability, tracked as CVE-2026-0273, found within its PAN-OS software. This severe flaw enables authenticated administrators to achieve root-level command execution through either the command-line interface (CLI) or the web management interface.
Table Of Content
Alongside this critical issue, the vendor also disclosed two related medium-severity vulnerabilities. These include a privilege escalation flaw in the CLI (CVE-2026-0272) and a denial-of-service vulnerability affecting tunnel traffic (CVE-2026-0269).
The Command Injection Vulnerability: CVE-2026-0273
The primary concern, CVE-2026-0273, is rated 6.1 under CVSS v4.0. It impacts PA-Series and VM-Series firewalls, as well as Panorama appliances operating on specific versions of PAN-OS 12.1, 11.2, 11.1, and 10.2. The vulnerability arises from insufficient input validation, which an authenticated administrator can exploit to bypass system safeguards and execute arbitrary operating system commands with root privileges. This can be done via both the CLI and the web-based management UI.
No special configurations are necessary for this vulnerability to be exploitable; any privileged user with login access to a vulnerable management interface puts the device at risk. Palo Alto Networks explicitly states that Cloud NGFW and Prisma Access services are not affected by this particular flaw.
Additional Vulnerabilities
CVE-2026-0272: CLI Privilege Escalation
This medium-severity vulnerability affects the PAN-OS CLI, allowing an authenticated administrator to elevate their privileges to root on the device. Similar to CVE-2026-0273, it impacts PA-Series, VM-Series, and Panorama devices across the 12.1, 11.2, 11.1, and 10.2 software trains, with Cloud NGFW and Prisma Access remaining unaffected.
CVE-2026-0269: Tunnel Traffic Denial-of-Service
This memory corruption vulnerability resides in the tunnel traffic processing component. An authenticated user can leverage this flaw by sending specially crafted packets, leading to repeated reboots of the firewall. Devices configured with IPsec tunnels or GlobalProtect gateways are susceptible. Persistent exploitation could force the firewall into maintenance mode, severely impacting its availability and operational status.
Palo Alto Networks has confirmed that it has no evidence of these three vulnerabilities being exploited maliciously in the wild at the time of their public disclosure.
Affected Versions and Patches
For CVE-2026-0273, affected PAN-OS branches include 12.1, 11.2, 11.1, and 10.2. Patches are available in hotfix versions such as 12.1.4-h7, 11.2.4-h18, 11.1.4-h34, and 10.2.7-h35, as well as subsequent maintenance releases like 12.1.7, 11.2.12, 11.1.15, and 10.2.18-h7.
CVE-2026-0272 and CVE-2026-0269 follow similar patching patterns, with fixes integrated into the latest “‑h” hotfixes and subsequent maintenance versions for each respective software train. Organizations still running older, unsupported PAN-OS branches are strongly advised to upgrade to a supported, patched release rather than relying solely on configuration workarounds.
| Product / PAN‑OS train | CVE ID | Affected versions (examples) | Fixed / upgrade to (examples) |
|---|---|---|---|
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0273 | 12.1: from 12.1.4 up to (but excluding) 12.1.4‑h7 and from 12.1.0 up to (but excluding) 12.1.7 | 12.1.4‑h7, 12.1.7 and later in the 12.1 line |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0273 | 11.2: from 11.2.4 up to (but excluding) 11.2.4‑h18; 11.2.7 up to 11.2.7‑h16; 11.2.10 up to 11.2.10‑h9; 11.2.0–<11.2.12 | 11.2.4‑h18, 11.2.7‑h16, 11.2.10‑h9, 11.2.12 and later in the 11.2 line |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0273 | 11.1: from 11.1.4 up to 11.1.4‑h34; 11.1.6 up to 11.1.6‑h33; 11.1.7 up to 11.1.7‑h7; 11.1.10 up to 11.1.10‑h27; 11.1.13 up to 11.1.13‑h7; 11.1.0–<11.1.15 | 11.1.4‑h34, 11.1.6‑h33, 11.1.7‑h7, 11.1.10‑h27, 11.1.13‑h7, 11.1.15 and later in 11.1 |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0273 | 10.2: from 10.2.7 up to 10.2.7‑h35; 10.2.10 up to 10.2.10‑h37; 10.2.13 up to 10.2.13‑h22; 10.2.16 up to 10.2.16‑h8; 10.2.18 up to 10.2.18‑h7 | 10.2.7‑h35, 10.2.10‑h37, 10.2.13‑h22, 10.2.16‑h8, 10.2.18‑h7 and later in 10.2 |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0272 | 12.1: 12.1.2 through 12.1.4‑h* (before 12.1.4‑h7) | 12.1.4‑h7, 12.1.5 or later in 12.1 |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0272 | 11.2: 11.2.0–<11.2.4‑h18; 11.2.5–<11.2.7‑h16; 11.2.8–<11.2.10‑h9; 11.2.10–<11.2.11 | 11.2.4‑h18, 11.2.7‑h16, 11.2.10‑h9, 11.2.11 and later in 11.2 |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0272 | 11.1: 11.1.0–<11.1.4‑h34; 11.1.5–<11.1.6‑h33; 11.1.7–<11.1.7‑h7; 11.1.8–<11.1.10‑h27; 11.1.11–<11.1.13‑h7; 11.1.13–<11.1.14 | 11.1.4‑h34, 11.1.6‑h33, 11.1.7‑h7, 11.1.10‑h27, 11.1.13‑h7, 11.1.14 and later in 11.1 |
| PA‑Series, VM‑Series, Panorama | CVE‑2026‑0272 | 10.2: 10.2.0–<10.2.7‑h35; 10.2.8–<10.2.10‑h37; 10.2.11–<10.2.13‑h22; 10.2.14–<10.2.16‑h8; 10.2.17–<10.2.18‑h5 | 10.2.7‑h35, 10.2.10‑h37, 10.2.13‑h22, 10.2.16‑h8, 10.2.18‑h5 and later in 10.2 |
| PA‑Series, VM‑Series (IPsec/GlobalProtect only) | CVE‑2026‑0269 | 12.1: 12.1.2–<12.1.4‑h5 and 12.1.0–<12.1.5 | 12.1.4‑h5, 12.1.5 and later in 12.1 |
| PA‑Series, VM‑Series (IPsec/GlobalProtect only) | CVE‑2026‑0269 | 11.2: 11.2.0–<11.2.4‑h17; 11.2.5–<11.2.7‑h4; 11.2.8–<11.2.9; 11.2.9–<11.2.10 | 11.2.4‑h17, 11.2.7‑h4, 11.2.10 and later in 11.2 |
| PA‑Series, VM‑Series (IPsec/GlobalProtect only) | CVE‑2026‑0269 | 11.1: 11.1.0–<11.1.4‑h33; 11.1.5–<11.1.6‑h21; 11.1.7–<11.1.10‑h7; 11.1.11–<11.1.12 | 11.1.4‑h33, 11.1.6‑h21, 11.1.10‑h7, 11.1.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.