Palo Alto stamped this one Suggested Urgency: HIGHEST. An unauthenticated attacker who can reach the management web or data plane can crash VM-Series — or run code as root on PA-Series hardware. Panorama is in scope too. No known exploit yet: that is the window, not a reason to wait.
No known exploit yet is the window, not a reason to wait.
What happened
CVE-2026-0310 is a buffer overflow in PAN-OS XML processing (CWE-787), published September 9, 2026. No special configuration is required to be affected. Impact splits by platform: PA-Series hardware faces arbitrary code execution as root (CVSS-B 9.2); VM-Series is primarily denial of service; Prisma Access and Cloud NGFW are lower (authenticated / restricted paths) and Palo Alto is upgrading those on the maintenance cycle.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Fixed trains are published per minor branch (examples: 12.2.3+, 12.1.10 / 12.1.7-h5 / 12.1.4-h10, and matching 11.2 / 11.1 / 10.2 hotfixes). Palo Alto reports no known malicious exploitation as of the advisory — which is the window you want to use, not waste.
Why it matters
Management-plane and dataplane reachability on next-gen firewalls is still too common on the open Internet. Root on a PA-Series box is policy, VPN, decryption, and a foothold into the trust fabric. “Urgency: HIGHEST” from the vendor with no known exploit yet is exactly when disciplined teams finish the upgrade — before scanner noise starts.
What to do first
- Inventory PAN-OS versions across PA-Series, VM-Series, and Panorama; map each to the fixed build in the advisory table.
- Upgrade to the listed fixed release for your train; do not stop at “recent hotfix” without checking the exact -h build.
- Restrict management interface access to a jump box / trusted nets only — Palo Alto’s own best-practice guidance materially lowers risk even before the patch.
- Confirm dataplane/management exposure with external attack-surface scans; close anything that should never have been public.
- Prisma Access / Cloud NGFW: verify Palo Alto’s scheduled upgrade or open an on-demand window with support if you need it sooner.
Forward this — Firewall owners: map every PAN-OS box to the fixed build in the advisory, take the upgrade, and lock management to a jump box while you do it.
Details
- CVE: CVE-2026-0310 — Out-of-bounds write via XML processing
- Impact: Unauth DoS (VM-Series) / unauth root RCE (PA-Series); Panorama impacted
- Urgency: HIGHEST (vendor)
- Exploit status: No known malicious exploitation (per Palo Alto)
- Workarounds: None known; network restriction reduces exposure
- Advisory: https://security.paloaltonetworks.com/CVE-2026-0310
Hunt / verify
- Record pre-upgrade PAN-OS version strings and confirm post-upgrade builds match the unaffected column.
- Review management and system logs for anomalous XML/API traffic to management or dataplane listeners in the pre-patch window.
- Validate management ACLs after change — patch plus exposure reduction.
Slack paste: Map PA/VM/Panorama versions to fixed builds; upgrade; restrict mgmt to jump box; confirm no public management listeners.
Sources
- https://security.paloaltonetworks.com/CVE-2026-0310
- https://nvd.nist.gov/vuln/detail/CVE-2026-0310
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.