Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software
CVE-2026-0310
Key Information:
- Vendor
Palo Alto Networks
- Vendor
- CVE Published:
- 10 September 2026
Badges
What is CVE-2026-0310?
CVE-2026-0310 is a critical buffer overflow vulnerability found in the Palo Alto Networks PAN-OS software, widely utilized for network security through its VM-Series and PA-Series firewalls. This vulnerability arises from flaws in the XML processing functionality of the software, allowing unauthenticated attackers with access to the management web or dataplane interface to potentially exploit it. The impact of this vulnerability can be severe, as it could lead to a denial of service (DoS) condition on VM-Series firewalls or even enable the execution of arbitrary code with root privileges on PA-Series firewalls. Organizations relying on Palo Alto Networks for their security infrastructure may find their systems compromised, leading to unauthorized access and control over critical network components.
Potential impact of CVE-2026-0310
-
Denial of Service (DoS): The vulnerability can cause a complete denial of service on affected VM-Series firewalls, interrupting organizational operations and potentially affecting business continuity.
-
Arbitrary Code Execution: Attackers may exploit this vulnerability to execute arbitrary code with root privileges on PA-Series firewalls, thus gaining full control over the affected device, leading to unauthorized access and manipulation of sensitive data.
-
Increased Attack Surface: With the management interface exposed to unauthenticated network access, organizations may face an increased risk of targeted attacks, particularly if best practices for securing management access are not followed, heightening the potential for exploitation by malicious actors.
Affected Version(s)
Cloud NGFW AWS All
PAN-OS 12.2.0 < 12.2.3
PAN-OS 12.1.0 < 12.1.4-h10
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved