PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

Plan PatchCVSS 7.8CVE-2026-0284Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of PAN-OS software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma Access are not impacted by this vulnerability.

What this means
What could happen
An attacker could inject malicious XML into VPN communications, potentially exposing VPN configuration data or corrupting the connection state between firewall satellites, which could disrupt secure remote access for your organization.
Who's at risk
Organizations using PAN-OS firewalls with Large Scale VPN (LSVPN) enabled should apply updates to affected versions. This affects companies with distributed firewall deployments that use LSVPN for satellite-to-hub communication in remote office or multi-site scenarios. Prisma Access users on affected versions also require updates.
How it could be exploited
An attacker with network access to the PAN-OS LSVPN interface sends specially crafted XML payloads to inject malicious content. This could allow them to read sensitive configuration data transmitted over LSVPN connections or corrupt the satellite synchronization data, affecting VPN connectivity.
Prerequisites
  • Network access to the LSVPN interface port on the PAN-OS firewall
  • LSVPN functionality enabled on the target PAN-OS device
remotely exploitableno authentication requiredlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (7)
7 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.4-h2011.2.4-h20+
Prisma AccessBelow 11.2.7-h1811.2.7-h18+
Prisma AccessBelow 11.2.10-h1211.2.10-h12+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/8
Do now
0/1
WORKAROUNDRestrict network access to the LSVPN interface to trusted satellite devices and administrative networks only
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.4-h8 or later if currently on 12.1.4 branch
HOTFIXUpdate PAN-OS to version 12.1.7-h2 or later if currently on 12.1.7 branch
HOTFIXUpdate PAN-OS to version 12.1.8 or later if currently on 12.1.8 branch
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.4-h20 or later if currently on 11.2.4 branch
HOTFIXUpdate Prisma Access to version 11.2.7-h18 or later if currently on 11.2.7 branch
HOTFIXUpdate Prisma Access to version 11.2.10-h12 or later if currently on 12.2.10 branch
HOTFIXUpdate Prisma Access to version 11.2.13 or later if currently on 11.2.13 branch
API: /api/v1/advisories/4bb0f35c-639f-4109-b5cc-1b4d0f30db9d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.