PAN-OS: Buffer Overflow Vulnerability via XML Processing

Plan PatchCVSS 9.2CVE-2026-0310Sep 9, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A buffer overflow in XML processing in Palo Alto Networks PAN-OS, Prisma Access, and Panorama allows an unauthenticated attacker with network access to the management web interface or dataplane interface to cause denial of service on VM-Series firewalls or execute arbitrary code with root privileges on PA-Series firewalls and Panorama. Cloud NGFW on AWS and Azure have no fix available. The vulnerability is mitigated when the management interface is restricted to trusted internal IP addresses.

What this means
What could happen
An attacker could cause firewalls to stop responding (denial of service) or, on some models, execute commands as root. This could halt network traffic and leave your facility without perimeter protection.
Who's at risk
Palo Alto Networks firewall administrators, particularly those running PAN-OS on PA-Series and VM-Series firewalls, Prisma Access deployments, Panorama management appliances, and Cloud NGFW instances on AWS or Azure. Any organization using these devices as network perimeter controls should treat this as critical.
How it could be exploited
An attacker with network access to the firewall's management interface or dataplane interface sends a specially crafted XML request. The vulnerable XML parser overflows and either crashes the firewall (DoS on VM-Series) or allows code execution with root privileges (PA-Series and Panorama).
Prerequisites
  • Network access to management interface or dataplane interface
  • No authentication required
remotely exploitableno authentication requiredaffects firewall availability and integrityno patch available for Cloud NGFW products
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (6)
4 with fix2 pending
ProductAffected VersionsFix Status
Cloud NGFWAll on AWS*No fix yet
Cloud NGFWAll on Azure*No fix yet
PAN-OSBelow 12.2.312.2.3+
Prisma AccessBelow 12.1.4-h1012.1.4-h10+
Prisma AccessBelow 12.1.7-h512.1.7-h5+
Prisma AccessBelow 12.1.1012.1.10+
Remediation & Mitigation
0/6
Do now
0/2
Cloud NGFW
HARDENINGIf using Cloud NGFW on AWS or Azure with no vendor fix available, implement network segmentation to limit access to the management interface from untrusted networks
All products
WORKAROUNDRestrict management interface access to only trusted internal IP addresses by updating firewall admin rules
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.2.3 or later
Prisma Access
HOTFIXUpdate Prisma Access to version 12.1.4-h10 or later (for affected versions below 12.1.4-h10)
HOTFIXUpdate Prisma Access to version 12.1.7-h5 or later (for affected versions below 12.1.7-h5)
HOTFIXUpdate Prisma Access to version 12.1.10 or later (for affected versions below 12.1.10)
API: /api/v1/advisories/1b98caa6-6b24-4a07-9dea-1f57a13c3851

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

PAN-OS: Buffer Overflow Vulnerability via XML Processing | CVSS 9.2 - OTPulse