CVE-2026-0310 PUBLISHED

PAN-OS: Buffer Overflow Vulnerability via XML Processing

Assigner: palo_alto
Reserved: 03.11.2025 Published: 10.09.2026 Updated: 10.09.2026

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.

The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

Panorama is impacted by this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red
CVSS Score: 7.2

The risk is highest for PA-Series hardware firewalls as there is a risk of arbitrary code execution

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 6.6

The risk is lower for VM-Series firewalls, as the impact is limited to a Denial of Service condition

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 4.8

The risk of exploitation is lower for Prisma Access and Cloud NGFW as it requires an authenticated user and the external network access is restricted.

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 5.2

You can reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface.

Product Status

Vendor Palo Alto Networks
Product Cloud NGFW
Versions Default: unaffected
  • Version All is affected
Vendor Palo Alto Networks
Product PAN-OS
Versions Default: unaffected
  • affected from 12.2.0 to 12.2.3 (excl.)
  • affected from 12.1.0 to 12.1.4-h10 (excl.)
  • affected from 11.2.0 to 11.2.4-h21 (excl.)
  • affected from 11.1.0 to 11.1.4-h36 (excl.)
  • affected from 10.2.0 to 10.2.7-h37 (excl.)
Vendor Palo Alto Networks
Product Prisma Access
Versions Default: unaffected
  • unaffected from 12.1.0 to 12.1.4-h10 (excl.)
  • affected from 11.2.0 to 11.2.4-h21 (excl.)
  • affected from 10.2.0 to 10.2.7-h37 (excl.)

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue. other

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE

Impacts

  • CAPEC-100 Overflow Buffers