Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software
CVE-2026-0310

5.2MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

Badges

๐Ÿ“ˆ Score: 1,550๐Ÿ‘พ Exploit Exists

What is CVE-2026-0310?

CVE-2026-0310 is a critical buffer overflow vulnerability found in the Palo Alto Networks PAN-OS software, widely utilized for network security through its VM-Series and PA-Series firewalls. This vulnerability arises from flaws in the XML processing functionality of the software, allowing unauthenticated attackers with access to the management web or dataplane interface to potentially exploit it. The impact of this vulnerability can be severe, as it could lead to a denial of service (DoS) condition on VM-Series firewalls or even enable the execution of arbitrary code with root privileges on PA-Series firewalls. Organizations relying on Palo Alto Networks for their security infrastructure may find their systems compromised, leading to unauthorized access and control over critical network components.

Potential impact of CVE-2026-0310

  1. Denial of Service (DoS): The vulnerability can cause a complete denial of service on affected VM-Series firewalls, interrupting organizational operations and potentially affecting business continuity.

  2. Arbitrary Code Execution: Attackers may exploit this vulnerability to execute arbitrary code with root privileges on PA-Series firewalls, thus gaining full control over the affected device, leading to unauthorized access and manipulation of sensitive data.

  3. Increased Attack Surface: With the management interface exposed to unauthenticated network access, organizations may face an increased risk of targeted attacks, particularly if best practices for securing management access are not followed, heightening the potential for exploitation by malicious actors.

Affected Version(s)

Cloud NGFW AWS All

PAN-OS 12.2.0 < 12.2.3

PAN-OS 12.1.0 < 12.1.4-h10

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
.