CVE-2026-0310 is a High-severity Palo Alto Networks PAN-OS vulnerability that requires administrators to check both product type and software version. Palo Alto Networks says an unauthenticated attacker with network access to an affected management web or dataplane interface may be able to execute arbitrary code with root privileges on PA-Series hardware firewalls. The vendor describes the VM-Series impact as denial of service and currently says it is not aware of malicious exploitation.
The key point is that CVE-2026-0310 does not have one identical consequence across every Palo Alto Networks product. Administrators should identify the exact product and PAN-OS release before deciding whether the deployment is affected and which fixed release is required.
What is CVE-2026-0310?
CVE-2026-0310 is a buffer-overflow vulnerability in PAN-OS XML processing. Palo Alto Networks says an unauthenticated attacker who has network access to the management web interface or a relevant dataplane interface can trigger the vulnerable processing path on affected systems.
The vendor currently rates the issue High under its CVSS 4.0 assessment. Older CVSS scoring shown by other vulnerability databases can differ, so administrators should not treat one score as a substitute for the vendor’s current product-specific impact guidance.
Which Palo Alto Networks products are affected?
Palo Alto Networks identifies affected PAN-OS firewall and management deployments, but the consequence differs by product type.
- PA-Series hardware firewalls: successful exploitation may allow arbitrary code execution with root privileges.
- VM-Series firewalls: the vendor describes the impact as denial of service.
- Panorama: affected versions are included in the vendor advisory and should be checked against the published fixed-version matrix.
- Prisma Access and Cloud NGFW: these managed products have a different exposure and severity model and should not be treated as equivalent to PA-Series hardware.
Does CVE-2026-0310 require authentication?
For the principal PA-Series and VM-Series exposure described by Palo Alto Networks, the attacker does not need to authenticate. The attacker does, however, need network access to the vulnerable management web or dataplane interface.
That network-access condition matters. A system that is not reachable through the relevant interface does not have the same exposure as an internet-accessible or otherwise reachable system, but administrators should verify the exact product and interface configuration rather than infer safety from product name alone.
Is special configuration required?
Palo Alto Networks says no special configuration is required for the vulnerability to exist on affected software. Exploitability still depends on network access to the relevant management web or dataplane interface.
Restricting management-interface access to trusted addresses can reduce risk, but it should not be treated as equivalent to upgrading to a fixed PAN-OS release because the vendor advisory also discusses dataplane-interface exposure.
Is CVE-2026-0310 actively exploited?
Palo Alto Networks currently says it is not aware of malicious exploitation of CVE-2026-0310. That is the current vendor state, not a guarantee that exploitation cannot occur later.
Because PA-Series hardware can face a root-code-execution consequence when the vulnerable path is reachable, administrators should base remediation on exposure and affected software state rather than wait for confirmed exploitation.
Which PAN-OS versions fix CVE-2026-0310?
The fix is branch-specific. Administrators should compare their exact running release against Palo Alto Networks’ current affected-and-fixed matrix rather than rely on one generic version number.
Examples confirmed in the current advisory and release documentation include:
- PAN-OS 12.2: upgrade affected 12.2.0 through 12.2.2 deployments to 12.2.3 or later.
- PAN-OS 12.1: fixed thresholds vary by minor branch and include fixed releases such as 12.1.4-h10, 12.1.7-h5 and 12.1.10.
- PAN-OS 11.2, 11.1 and 10.2: Palo Alto Networks publishes branch-specific hotfix thresholds that must be checked against the exact installed release.
Do not extrapolate one fixed version across all branches. The safe verification method is to identify the exact product and PAN-OS build, then compare it directly with the current vendor matrix.
What should administrators do with unsupported PAN-OS versions?
Palo Alto Networks advises customers running unsupported PAN-OS versions to move to a supported release that contains the fix. An end-of-support deployment should therefore be treated as an upgrade or migration problem rather than assuming a new hotfix will be released for that branch.
What about Prisma Access and Cloud NGFW?
Palo Alto Networks treats Prisma Access and Cloud NGFW differently from PA-Series hardware in its advisory. The vendor rates these managed-service cases lower than the PA-Series hardware scenario and says affected managed customers will be upgraded during a scheduled maintenance cycle.
Customers that need an earlier managed-service upgrade should use Palo Alto Networks’ current support or account-management route. The exact tenant upgrade state cannot be inferred from the public advisory alone.
How can an administrator verify remediation?
Confirm whether the deployment is PA-Series, VM-Series, Panorama, Prisma Access or Cloud NGFW.
Check the running PAN-OS version and hotfix level rather than relying on a major-version label.
Verify whether that exact branch is below Palo Alto Networks’ fixed threshold.
Upgrade affected systems to the applicable fixed PAN-OS release or vendor-managed service state.
Confirm that the running version is at or beyond the vendor’s fixed threshold and preserve that patch state in the security record.
Why PA-Series and VM-Series should not be treated the same
The vendor’s current consequence assessment is materially different. PA-Series hardware can face arbitrary code execution with root privileges, while the VM-Series impact is described as denial of service. A generic statement that every affected Palo Alto firewall can be remotely rooted would therefore overstate the evidence.
What happens next?
The most important developments to monitor are a Palo Alto Networks advisory revision, evidence of malicious exploitation, CISA Known Exploited Vulnerabilities status, new indicators of compromise or detection guidance, revised affected-version ranges, or changes to managed-service upgrade timing.
Those developments should update this same CVE-2026-0310 page while the reader’s core job remains verifying exposure and reaching a fixed software state.
Verification note
TPS reviewed Palo Alto Networks’ CVE-2026-0310 advisory and current PAN-OS release documentation, with current government and industry security advisories used for corroboration. The vulnerability, product-specific consequences and fixed-version guidance are confirmed; future exploitation, exposed-device counts, CVE-specific indicators and individual managed-service upgrade completion remain unresolved.



