Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryperimeter-device-exposureembedded-device-vulnerabilityprivilege-escalation-method

Palo Alto PAN-OS Flaws Enable Root Command Execution, Privilege Escalation, and DoS

Updated 7d agoFirst seen Jun 10, 20265 sources

Palo Alto Networks disclosed and patched multiple vulnerabilities in PAN-OS affecting PA-Series, VM-Series, and Panorama, including CVE-2026-0273, an authenticated administrator command injection flaw in the CLI and web management interface that can allow arbitrary commands to run as root. The vendor also fixed CVE-2026-0272, an authenticated CLI privilege escalation issue, and CVE-2026-0266, a stored XSS vulnerability in the web interface. A separate issue, CVE-2026-0269, can trigger a denial of service through crafted tunnel traffic and repeatedly reboot affected firewalls, potentially forcing them into maintenance mode.

Affected versions span supported PAN-OS 12.1, 11.2, 11.1, and 10.2 release trains, while Cloud NGFW and Prisma Access were reported as unaffected. Palo Alto Networks said it was not aware of active exploitation at disclosure time and urged customers to upgrade promptly, restrict management access to trusted internal IPs, limit CLI exposure, and use hardened jump boxes; for CVE-2026-0273, organizations with Threat Prevention can also enable dedicated Threat IDs to help block exploit attempts when management traffic is inspectable and decrypted.

Share:
Palo Alto PAN-OS Flaws Enable Root Command Execution, Privilege Escalation, and DoS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 10, 20269d ago

Palo Alto says no malicious exploitation was known at disclosure

In its disclosure coverage, Palo Alto Networks said it was not aware of malicious exploitation of the PAN-OS vulnerabilities at the time of disclosure. The company recommended prompt upgrades and mitigation steps including restricting management and CLI access.

Palo Alto PAN-OS Vulnerability Allow Attackers to Arbitrary Commands as a Root User

Palo Alto discloses and fixes four PAN-OS vulnerabilities

On June 10, 2026, Palo Alto Networks published advisories for CVE-2026-0273, CVE-2026-0272, CVE-2026-0266, and CVE-2026-0269 affecting PAN-OS. The issues include authenticated command injection, CLI privilege escalation, stored XSS, and a tunnel-traffic denial-of-service flaw.

CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
7 linked
Pan-OsPrisma AccessCloud NgfwPanoramaVm-SeriesPa-SeriesGlobalprotect
Organizations
1 linked
Palo Alto Networks
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.