Palo Alto PAN-OS Critical Vulnerability Lets Attackers Execute Code as Root
Key Takeaways A critical vulnerability, CVE-2026-0310, has been disclosed in Palo Alto Networks PAN-OS. It affects PA-Series hardware firewalls, VM-Series firewalls, Prisma Access, and Cloud NGFW...
Key Takeaways
- A critical vulnerability, CVE-2026-0310, has been disclosed in Palo Alto Networks PAN-OS.
- It affects PA-Series hardware firewalls, VM-Series firewalls, Prisma Access, and Cloud NGFW environments.
- For PA-Series hardware, the flaw allows unauthenticated remote code execution with root privileges, earning a CVSS base score of 9.2.
- Patches are available across multiple PAN-OS release branches; immediate upgrades are strongly recommended.
Palo Alto Networks Discloses Critical PAN-OS Vulnerability Enabling Root-Level Remote Code Execution
Palo Alto Networks has issued an urgent advisory regarding a severe vulnerability in its PAN-OS software, which could enable an unauthenticated remote attacker to achieve arbitrary code execution with root privileges on certain PA-Series hardware firewalls. This flaw, identified as CVE-2026-0310, carries the highest recommended urgency from the vendor.
Table Of Content
Technical Details and Impact
The vulnerability stems from improper XML processing, specifically categorized as a buffer overflow (CWE-787: Out-of-bounds Write). An attacker with network access to either a vulnerable management web interface or a dataplane interface could exploit this by sending specially crafted XML data. Successful exploitation on PA-Series appliances grants the attacker complete control over the firewall’s operating environment, as code execution occurs with root user privileges.
Such a compromise of an enterprise perimeter firewall poses a grave security risk. A threat actor could manipulate security policies, intercept or reroute network traffic, establish persistent access, exfiltrate configuration data, or leverage the compromised device as a pivot point for further attacks into internal networks.
Palo Alto Networks has assigned CVE-2026-0310 a CVSS-BT score of 7.2 and a CVSS-B base score of 9.2 for affected PA-Series firewalls. While exploitation does not require authentication or user interaction, the vendor rates its complexity as high. The practical risk is most significant for physical firewall appliances due to the potential for root-level remote code execution.
Impact Across Product Lines
The implications of this vulnerability vary across Palo Alto Networks’ product portfolio. On vulnerable VM-Series firewalls, exploitation leads to a denial-of-service (DoS) condition rather than code execution. A successful attack could crash or disrupt the virtual firewall, impacting traffic inspection and overall availability. Prisma Access and Cloud NGFW environments are also affected, though the vendor assesses the risk as lower in these instances because exploitation demands an authenticated user and external network access is more restricted.
Affected Versions and Remediation
Affected PAN-OS releases include versions prior to 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10, depending on the specific release branch. Numerous maintenance builds across the 10.2, 11.1, 11.2, and 12.1 branches are also susceptible. Palo Alto Networks recommends upgrading immediately to the appropriate patched release, with PAN-OS 12.2.3 or later advised for the 12.2 branch.
As of September 9, 2026, Palo Alto Networks stated it discovered CVE-2026-0310 internally and is not aware of any active malicious exploitation in the wild.
What You Should Do
- Upgrade Immediately: Apply the recommended PAN-OS updates as soon as possible. For the 12.2 branch, upgrade to PAN-OS 12.2.3 or later. Consult the official advisory for specific patch versions relevant to your deployment.
- Restrict Management Access: Ensure that firewall management interfaces are not exposed to untrusted networks. Limit access to trusted internal IP addresses.
- Utilize Jump Boxes: Where feasible, configure administration access to PAN-OS devices only through a dedicated jump box, adding an extra layer of security.
- Monitor for Anomalies: Continuously monitor firewall logs and network traffic for any unusual activity that could indicate an attempted or successful exploitation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.