Published on September 10, 2026
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Severity
Critical
Palo Alto Networks has disclosed a high-severity buffer overflow vulnerability in PAN-OS that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls.
The vulnerability is tracked as CVE-2026-0310 and is caused by improper processing of XML data within PAN-OS. The issue affects both firewall management web interfaces and dataplane interfaces. An attacker may exploit the vulnerability remotely without authentication, special privileges, user interaction, or specific device configurations.
| CVE ID | Summary | CVSS Score |
| CVE-2026-0310 | Buffer overflow vulnerability in PAN-OS XML processing that may allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series firewalls. | 9.2 (Critical) |
The vulnerability is classified as CWE-787 (Out-of-bounds Write). Successful exploitation against PA-Series hardware firewalls could provide an attacker with root-level access to a perimeter security device. This could potentially allow the attacker to modify firewall security policies, disable security controls, intercept or manipulate network traffic, establish persistence, or use the compromised firewall as a pivot point into the internal network.
Palo Alto Networks published the advisory on September 9, 2026, assigning the vulnerability a CVSS v4.0 score of 9.2 and a CVSS-BT score of 7.2. The vendor has classified the recommended remediation urgency as “highest.”
The vulnerability affects multiple PAN-OS release branches. For PAN-OS 12.2, users should upgrade to 12.2.3 or later. For PAN-OS 12.1, fixed versions include 12.1.4-h10, 12.1.7-h5, and 12.1.10, depending on the supported maintenance train. Fixed releases are also available for PAN-OS 11.2, 11.1, and 10.2.
Unsupported PAN-OS releases may remain vulnerable and should be migrated to supported versions. Palo Alto Networks has also indicated that no special configuration is required for a device to be vulnerable.
Affected Products
| Product | Impact | Severity |
| PA-Series Firewalls | Potential arbitrary code execution with root privileges | High |
| VM-Series Firewalls | Potential denial-of-service condition | Medium |
| Prisma Access | Reduced exposure; authenticated access required | Medium |
| Cloud NGFW | Reduced exposure; authenticated access required | Medium |
The highest risk is associated with PA-Series hardware firewalls, where successful exploitation could result in arbitrary code execution with root privileges. VM-Series firewalls are primarily exposed to a denial-of-service condition, which could nevertheless affect network connectivity and security inspection capabilities.
Recommendation
Organizations should prioritize upgrading affected PAN-OS appliances to the appropriate vendor-provided fixed release. There is currently no workaround, making software updates the primary remediation measure.
Priority should be given to internet-facing PA-Series firewalls, as successful exploitation could provide an attacker with privileged control over a critical network security device.
Administrators should also:
- Upgrade affected PAN-OS installations to the appropriate fixed maintenance release.
- Identify unsupported PAN-OS versions and migrate them to supported releases.
- Restrict firewall management interfaces to trusted internal networks and authorized administrative systems.
- Where possible, use a dedicated jump host as the only system permitted to access the firewall management interface.
- Review administrative access rules and externally exposed HTTPS or management services.
- Monitor for unexpected firewall configuration changes, restarts, or other abnormal administrative activity.
- Investigate unusual XML-related requests and network activity targeting affected firewall interfaces.
- Review recent administrative authentication and configuration activity for signs of unauthorized access.
Although Palo Alto Networks has stated that it is not currently aware of active exploitation, the combination of unauthenticated remote access and potential root-level code execution presents a significant risk. Organizations should therefore treat remediation as a high priority, particularly for internet-exposed PA-Series appliances.
Source
