Palo Alto Networks disclosed CVE-2026-0310, a high-severity XML-processing buffer overflow in PAN-OS that can allow an unauthenticated remote attacker to execute arbitrary code as root on affected PA-Series hardware firewalls. The flaw, scored 9.2 CVSS-B, is reachable through vulnerable management-web or dataplane interfaces using specially crafted XML; exploitation is considered high complexity. On VM-Series appliances, the impact is limited to denial of service, while Prisma Access and Cloud NGFW deployments face more restricted exposure because exploitation requires authentication and their external interfaces are less accessible.
Palo Alto Networks released fixed PAN-OS versions and states that no workaround is available; administrators should immediately apply the vendor updates and restrict management access to trusted networks. Canadian and Italian government advisories also identify affected PAN-OS, Prisma Access, and Cloud NGFW on AWS and Azure products, and flag PAN-SA-2026-0012 for Chromium vulnerabilities affecting Prisma Browser versions before 151.26.5.170. Palo Alto reported no known exploitation of CVE-2026-0310 in the wild as of September 9, 2026.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-905 concerning vulnerabilities affecting Palo Alto Networks products, including CVE-2026-0310 and PAN-SA-2026-0012 for Chromium's September 2026 update. The advisory listed Cloud NGFW on AWS and Azure, PAN-OS, Prisma Access, and Prisma Browser as affected and urged administrators to apply available updates.
As of September 9, 2026, Palo Alto Networks stated it was not aware of malicious exploitation in the wild of CVE-2026-0310.
Palo Alto Networks disclosed CVE-2026-0310, a high-severity XML-processing buffer overflow that can permit unauthenticated remote root-level code execution on affected PA-Series firewalls; exploitation on VM-Series is limited to denial of service. The company released fixed PAN-OS versions and stated that no workaround is available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
7 references tracked. Mallory keeps watching after this page renders.
socprime.com
Open sourcemalware.news
Open sourceacn.gov.it
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.