logo

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

ID: 3ad92444-88c5-57eb-af3e-67c4e004eaaa

STIX ID: report--3ad92444-88c5-57eb-af3e-67c4e004eaaa

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Divya

...
...

Palo Alto Networks disclosed CVE-2026-0310, a high-severity PAN-OS XML buffer overflow (CVSS v4.0 base score 9.2) that can enable unauthenticated remote code execution as root on PA-Series hardware firewalls; VM-Series and cloud offerings face reduced impacts. Affected PAN-OS releases include 10.2, 11.1, 11.2, 12.1, and 12.2 with specific fixed maintenance releases provided; no workaround exists so administrators are urged to urgently apply vendor patches, limit management access to trusted IPs or jump boxes, and monitor for anomalous XML requests—Palo Alto reports no observed exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.