Palo Alto says HIGHEST urgency — root risk on PA-Series firewalls

By George Bailey   Published: 09/24/26   3 min read

Palo Alto stamped this one Suggested Urgency: HIGHEST. An unauthenticated attacker who can reach the management web or data plane can crash VM-Series — or run code as root on PA-Series hardware. Panorama is in scope too. No known exploit yet: that is the window, not a reason to wait.

No known exploit yet is the window, not a reason to wait.

What happened

CVE-2026-0310 is a buffer overflow in PAN-OS XML processing (CWE-787), published September 9, 2026. No special configuration is required to be affected. Impact splits by platform: PA-Series hardware faces arbitrary code execution as root (CVSS-B 9.2); VM-Series is primarily denial of service; Prisma Access and Cloud NGFW are lower (authenticated / restricted paths) and Palo Alto is upgrading those on the maintenance cycle.

Fixed trains are published per minor branch (examples: 12.2.3+, 12.1.10 / 12.1.7-h5 / 12.1.4-h10, and matching 11.2 / 11.1 / 10.2 hotfixes). Palo Alto reports no known malicious exploitation as of the advisory — which is the window you want to use, not waste.

Why it matters

Management-plane and dataplane reachability on next-gen firewalls is still too common on the open Internet. Root on a PA-Series box is policy, VPN, decryption, and a foothold into the trust fabric. “Urgency: HIGHEST” from the vendor with no known exploit yet is exactly when disciplined teams finish the upgrade — before scanner noise starts.

What to do first

Forward this — Firewall owners: map every PAN-OS box to the fixed build in the advisory, take the upgrade, and lock management to a jump box while you do it.

Details

Hunt / verify

Slack paste: Map PA/VM/Panorama versions to fixed builds; upgrade; restrict mgmt to jump box; confirm no public management listeners.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.