Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
ID: 3ad92444-88c5-57eb-af3e-67c4e004eaaa
STIX ID: report--3ad92444-88c5-57eb-af3e-67c4e004eaaa
Feed Name: GBHackers
Palo Alto Networks disclosed CVE-2026-0310, a high-severity PAN-OS XML buffer overflow (CVSS v4.0 base score 9.2) that can enable unauthenticated remote code execution as root on PA-Series hardware firewalls; VM-Series and cloud offerings face reduced impacts. Affected PAN-OS releases include 10.2, 11.1, 11.2, 12.1, and 12.2 with specific fixed maintenance releases provided; no workaround exists so administrators are urged to urgently apply vendor patches, limit management access to trusted IPs or jump boxes, and monitor for anomalous XML requests—Palo Alto reports no observed exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
