securityonline.info 9 Sept 2026, 17:05 UTC

Palo Alto Firewalls Exposed to Root Code Execution Flaw in PAN-OS

Palo Alto Firewalls Exposed to Root Code Execution Flaw in PAN-OS
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ON 9 September 2026, Palo Alto Networks disclosed a high-severity vulnerability in PAN-OS (CVE-2026-0310) that could allow unauthenticated remote attackers to execute arbitrary code with root privileges or cause a denial of service. The flaw resides in the XML processing functionality of PAN-OS, with an attacker needing network access to the management web or dataplane interface to trigger it by sending crafted XML requests.

The advisory notes that exploitation could grant full control over PA-Series firewalls or disrupt VM-Series devices, underscoring a potentially widespread impact given the platform’s use across many enterprises.

The vulnerability affects a wide range of PAN-OS versions across multiple models, including PAN-OS 10.2, 11.1, 11.2, 12.1, and 12.2, along with Cloud NGFW on AWS/Azure and Prisma Access deployments. At present, security researchers have not confirmed active exploitation, and no public PoC has been released. The recommended mitigations are to upgrade to fixed releases—PAN-OS 12.2.3, 12.1.10, or 11.2.13-h2—and to limit exposure by restricting management interface access to trusted internal IP addresses. This approach aims to reduce the risk of unauthorised access while devices are being updated.

View full article

Article by CyberSIXT