CVE-2026-0310
Received
Received - Intake
Buffer Overflow in PAN-OS XML Processing
Vulnerability report for CVE-2026-0310, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-10
Last updated on: 2026-09-10
Assigner: Palo Alto Networks, Inc.
Description
Description
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.
The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
Panorama is impacted by this vulnerability.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| palo_alto_networks | pan-os | 10.2 |
| palo_alto_networks | pan-os | 11.1 |
| palo_alto_networks | pan-os | 11.2 |
| palo_alto_networks | pan-os | 12.1 |
| palo_alto_networks | pan-os | 12.2 |
| palo_alto_networks | prisma_access | 10.2 |
| palo_alto_networks | prisma_access | 11.2 |
| palo_alto_networks | prisma_access | 12.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |