Executive brief
Palo Alto Networks PAN-OS is the operating system for enterprise firewalls that protect networks from unauthorized access and threats. A buffer overflow vulnerability in XML processing allows unauthenticated attackers with network access to cause service outages on VM-Series firewalls or execute malicious code with full system privileges on PA-Series hardware firewalls. This affects critical network infrastructure that organizations rely on to defend their networks.
Technical details
This is a CWE-787 out-of-bounds write (buffer overflow) in the XML processing functionality of PAN-OS. The vulnerability is triggered when parsing specially crafted XML input on either the management web interface or dataplane interface. No authentication or special configuration is required for exploitation, and the attack complexity is rated as high. On PA-Series hardware firewalls, successful exploitation enables arbitrary code execution with root privileges; on VM-Series virtual firewalls, it results in denial of service. Panorama centralized management systems are also affected. Patches are available for all supported versions across PAN-OS 10.2, 11.1, 11.2, and 12.1/12.2 branches, as well as Prisma Access and Cloud NGFW deployments.
Affected products
- Palo Alto Networks PAN-OS 10.2.0–10.2.18, 11.1.0–11.1.16, 11.2.0–11.2.13, 12.1.2–12.1.9
- Palo Alto Networks Panorama Multiple versions affected
- Palo Alto Networks Prisma Access 10.2.0–10.2.x, 11.2.0–11.2.x, 12.1.2–12.1.x
- Palo Alto Networks Cloud NGFW Multiple versions affected
Timeline
- 2026-09-09: disclosed: CVE-2026-0310 published by Palo Alto Networks
- 2026-09-10: other: Advisory published to NVD