Palo Alto Networks disclosed and patched multiple vulnerabilities in PAN-OS affecting PA-Series, VM-Series, and Panorama, including CVE-2026-0273, an authenticated administrator command injection flaw in the CLI and web management interface that can allow arbitrary commands to run as root. The vendor also fixed CVE-2026-0272, an authenticated CLI privilege escalation issue, and CVE-2026-0266, a stored XSS vulnerability in the web interface. A separate issue, CVE-2026-0269, can trigger a denial of service through crafted tunnel traffic and repeatedly reboot affected firewalls, potentially forcing them into maintenance mode.
Affected versions span supported PAN-OS 12.1, 11.2, 11.1, and 10.2 release trains, while Cloud NGFW and Prisma Access were reported as unaffected. Palo Alto Networks said it was not aware of active exploitation at disclosure time and urged customers to upgrade promptly, restrict management access to trusted internal IPs, limit CLI exposure, and use hardened jump boxes; for CVE-2026-0273, organizations with Threat Prevention can also enable dedicated Threat IDs to help block exploit attempts when management traffic is inspectable and decrypted.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
In its disclosure coverage, Palo Alto Networks said it was not aware of malicious exploitation of the PAN-OS vulnerabilities at the time of disclosure. The company recommended prompt upgrades and mitigation steps including restricting management and CLI access.
On June 10, 2026, Palo Alto Networks published advisories for CVE-2026-0273, CVE-2026-0272, CVE-2026-0266, and CVE-2026-0269 affecting PAN-OS. The issues include authenticated command injection, CLI privilege escalation, stored XSS, and a tunnel-traffic denial-of-service flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurity.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.