CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE
CVE-2026-0310 (TL-2026-2440) is a critical-severity software vulnerability scored CVSS 9.2, first published 2026-09-10. It has no confirmed attribution, affects Palo Alto Networks PAN-OS (PA-Series hardware firewalls), references 1 CVE (CVE-2026-0310), maps to 9 MITRE ATT&CK techniques (T1098, T1136.001, T1190), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2440
- Threat ID
- TL-2026-2440
- Severity
- CRITICAL
- CVSS
- 9.2 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-10
- Last reviewed
- 2026-09-10
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 8
A CWE-787 out-of-bounds write in PAN-OS XML processing lets an unauthenticated network attacker with access to the management web interface or dataplane interface execute arbitrary code as root on PA-Series firewalls, or cause a denial-of-service condition on VM-Series. Palo Alto Networks discovered the flaw internally; as of publication (2026-09-09/10) there is no known in-the-wild exploitation, no public proof-of-concept, and it is not in the CISA KEV catalog.
How CVE-2026-0310 works
CVE-2026-0310 is a buffer overflow (CWE-787, out-of-bounds write; CAPEC-100 Overflow Buffers) in the XML processing functionality of Palo Alto Networks PAN-OS. An unauthenticated attacker who can reach the management web interface or the dataplane interface can send specially crafted XML data to trigger memory corruption. On PA-Series hardware firewalls the flaw can be leveraged for arbitrary code execution with root privileges; on VM-Series virtual firewalls the same flaw is limited to a denial-of-service condition. Panorama is impacted across the same vulnerable PAN-OS branches. Cloud NGFW on AWS and Azure (all versions as of disclosure) are also affected, and Prisma Access is affected at materially lower risk (CVSS v4.0 4.8, adjacent-network vector, authentication required), substantially reducing its exposure relative to on-premises PA-Series/VM-Series/Panorama deployments.
No special configuration is required for a device to be vulnerable, and the vendor states no workaround exists short of upgrading; risk is minimized (not eliminated) by restricting the management interface to trusted internal IP addresses. Exploit complexity is rated high (CVSS v4.0 AC:H) but the base severity for the PA-Series root-RCE scenario is 9.2 (CRITICAL) -- network attack vector, no privileges or user interaction required, full confidentiality/integrity/availability impact -- while the threat-adjusted CVSS-BT score (reflecting unreported exploit maturity) is 7.2. VM-Series scores CVSS-B 8.7 / CVSS-BT 6.6 (availability impact only). The vendor's own risk narrative for a successfully exploited PA-Series device describes an attacker able to alter security policies, inspect or redirect inspected traffic, deploy persistence, and steal device configuration -- full compromise of a network perimeter/boundary control point, not merely a crash. Independent reporting adds that root access could let an attacker disable protections, intercept or manipulate traffic, and use the device as an internal pivot point for further network attacks.
Palo Alto Networks discovered and disclosed the vulnerability internally; there is no confirmed threat-actor exploitation, no public PoC, and it does not appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-10 (confirmed against CISA's recent KEV-addition alerts, none of which name CVE-2026-0310). Given the criticality of PAN-OS firewalls as internet- and network-facing perimeter devices, and the industry-wide history of PAN-OS management-interface vulnerabilities being weaponized shortly after disclosure, defenders should treat this as a high-priority, patch-now advisory even in the absence of confirmed exploitation.
MITRE ATT&CK techniques used in TL-2026-2440
Persistence
T1098 Account Manipulation; T1136.001 Local Account
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Collection
T1557 Adversary-in-the-Middle; T1602.002 Network Device Configuration Dump
Reconnaissance
T1595.002 Vulnerability Scanning
defense-impairment
T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall
Affected products and versions in CVE-2026-0310
- Palo Alto Networks — PAN-OS (PA-Series hardware firewalls)
Vulnerable versions: 10.2.x < 10.2.18-h10; 11.1.x < 11.1.16-h2; 11.2.x < 11.2.13-h2; 12.1.x < 12.1.10; 12.2.x < 12.2.3
Fixed in: 10.2.18-h10; 11.1.16-h2; 11.2.13-h2; 12.1.10; 12.2.3 - Palo Alto Networks — PAN-OS (VM-Series virtual firewalls)
Vulnerable versions: 10.2.x < 10.2.18-h10; 11.1.x < 11.1.16-h2; 11.2.x < 11.2.13-h2; 12.1.x < 12.1.10; 12.2.x < 12.2.3
Fixed in: 10.2.18-h10; 11.1.16-h2; 11.2.13-h2; 12.1.10; 12.2.3 - Palo Alto Networks — Panorama
Vulnerable versions: Same PAN-OS branches as PA-Series/VM-Series prior to fixed builds
Fixed in: 10.2.18-h10; 11.1.16-h2; 11.2.13-h2; 12.1.10; 12.2.3 - Palo Alto Networks — Cloud NGFW for AWS
Vulnerable versions: All versions as of disclosure
Fixed in: Vendor-managed; no customer action specified in advisory - Palo Alto Networks — Cloud NGFW for Azure
Vulnerable versions: All versions as of disclosure
Fixed in: Vendor-managed; no customer action specified in advisory - Palo Alto Networks — Prisma Access
Vulnerable versions: Select versions; CVSS v4.0 4.8 (adjacent-network vector); exploitation requires authentication
Fixed in: Vendor-managed; no customer action specified in advisory
Remediation for CVE-2026-0310
Patches
- PAN-OS 12.2.3 or later
- PAN-OS 12.1.4-h10, 12.1.7-h5, or 12.1.10
- PAN-OS 11.2.4-h21, 11.2.7-h20, 11.2.10-h14, or 11.2.13-h2
- PAN-OS 11.1.4-h36, 11.1.6-h38, 11.1.7-h10, 11.1.10-h33, 11.1.13-h12, or 11.1.16-h2
- PAN-OS 10.2.7-h37, 10.2.10-h40, 10.2.13-h24, 10.2.16-h10, or 10.2.18-h10
Immediate actions
- Restrict management interface access to trusted internal IP addresses only
- Deploy administrative access through a dedicated jump-box model rather than direct exposure
- Prevent internet/untrusted-network exposure of the PAN-OS management web interface and dataplane interface
- Segment management access onto a dedicated management VLAN separate from production data paths
Workarounds
- No official workaround exists; restricting management/dataplane interface exposure to trusted networks and jump boxes reduces (but does not eliminate) risk pending patch deployment
Longer-term hardening
- Upgrade to a fixed PAN-OS release for your branch (12.2.3+, 12.1.10+, 11.2.13-h2+, 11.1.16-h2+, or 10.2.18-h10+)
- Monitor for anomalous/malformed XML-formatted requests, unexpected PAN-OS service restarts, and unauthorized administrative configuration or account changes
- Review recent administrative access logs and configuration-change history for anomalies predating patch deployment
CVEs associated with CVE-2026-0310
Weaknesses (CWE) in CVE-2026-0310
CWE-787
Timeline of CVE-2026-0310
- Palo Alto Networks and independent outlets report exploit maturity as unreported/unknown -- no confirmed active exploitation and no public proof-of-concept exploit for CVE-2026-0310.
- cybersecuritynews.com, gbhackers.com, securityonline.info, and cyberpress.org publish independent technical write-ups summarizing the buffer-overflow root cause and post-exploitation attack scenarios (policy tampering, traffic redirection/interception, persistence, configuration theft, internal pivoting).
- SOCPrime publishes an analysis blog covering detection guidance (malformed XML traffic, unexpected restarts, unauthorized account changes, logging-disable attempts, management VLAN segmentation) for CVE-2026-0310.
- Palo Alto Networks PSIRT publishes the CVE-2026-0310 advisory, rating it CVSS-B 9.2 (CVSS-BT 7.2) for PA-Series root RCE, CVSS-B 8.7 (CVSS-BT 6.6) for VM-Series DoS, and CVSS 4.8 for Prisma Access/Cloud NGFW, with fixed builds across all supported PAN-OS branches.
- Palo Alto Networks internally discovers CVE-2026-0310 during internal security research; no external report or customer incident triggered discovery.
- CVE-2026-0310 does not appear in the CISA Known Exploited Vulnerabilities catalog as of this date; none of CISA's recent KEV-addition alerts (Aug-Sep 2026) name this CVE.
- NVD record for CVE-2026-0310 last modified (14:50:07 UTC).
- NVD publishes the CVE-2026-0310 record (06:17:04 UTC) with CVSS v4.0 base score 9.2 (CVSS-BT 7.2) and CWE-787 classification, status 'Awaiting Analysis'.
Sources cited for CVE-2026-0310
- CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing
- CVE-2026-0310: Critical PAN-OS Buffer Overflow Flaw
- Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User
- Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
- CVE-2026-0310: PAN-OS Buffer Overflow Flaw Allows Execute Arbitrary Code with Root Privileges
- Palo Alto PAN-OS Flaw Lets Unauthenticated Attackers Execute Code as Root
- CVE-2026-0310 Detail
- NVD CVE-2026-0310 API Record
More in vulnerability
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)
- Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices
- Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector
- Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write, chained with Dolby decoder RCE (CVE-2025-54957)
Detection coverage for TL-2026-2440
As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2440 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.