LATEST View all updates

CVE-2026-0310: PAN-OS Affected Versions and Fixed Releases

Palo Alto CVE-2026-0310 affects PAN-OS products differently. Check affected versions, fixed releases and current exploitation status.

Enterprise firewall vulnerability being remediated across hardware and virtual firewall infrastructure

Signal Brief

  • CVE-2026-0310 is a High-severity PAN-OS buffer overflow that can allow unauthenticated root-code execution on affected PA-Series hardware when the vulnerable interface is reachable.
  • VM-Series has a different documented consequence: Palo Alto Networks describes the impact as denial of service rather than the PA-Series root-RCE outcome.
  • Administrators should compare the exact PAN-OS branch and hotfix level with Palo Alto Networks' current fixed-version matrix instead of relying on one generic version number.
  • Palo Alto Networks currently says it is not aware of malicious exploitation of CVE-2026-0310.

CVE-2026-0310 is a High-severity Palo Alto Networks PAN-OS vulnerability that requires administrators to check both product type and software version. Palo Alto Networks says an unauthenticated attacker with network access to an affected management web or dataplane interface may be able to execute arbitrary code with root privileges on PA-Series hardware firewalls. The vendor describes the VM-Series impact as denial of service and currently says it is not aware of malicious exploitation.

The key point is that CVE-2026-0310 does not have one identical consequence across every Palo Alto Networks product. Administrators should identify the exact product and PAN-OS release before deciding whether the deployment is affected and which fixed release is required.

What is CVE-2026-0310?

CVE-2026-0310 is a buffer-overflow vulnerability in PAN-OS XML processing. Palo Alto Networks says an unauthenticated attacker who has network access to the management web interface or a relevant dataplane interface can trigger the vulnerable processing path on affected systems.

The vendor currently rates the issue High under its CVSS 4.0 assessment. Older CVSS scoring shown by other vulnerability databases can differ, so administrators should not treat one score as a substitute for the vendor’s current product-specific impact guidance.

Which Palo Alto Networks products are affected?

Palo Alto Networks identifies affected PAN-OS firewall and management deployments, but the consequence differs by product type.

  • PA-Series hardware firewalls: successful exploitation may allow arbitrary code execution with root privileges.
  • VM-Series firewalls: the vendor describes the impact as denial of service.
  • Panorama: affected versions are included in the vendor advisory and should be checked against the published fixed-version matrix.
  • Prisma Access and Cloud NGFW: these managed products have a different exposure and severity model and should not be treated as equivalent to PA-Series hardware.

Does CVE-2026-0310 require authentication?

For the principal PA-Series and VM-Series exposure described by Palo Alto Networks, the attacker does not need to authenticate. The attacker does, however, need network access to the vulnerable management web or dataplane interface.

That network-access condition matters. A system that is not reachable through the relevant interface does not have the same exposure as an internet-accessible or otherwise reachable system, but administrators should verify the exact product and interface configuration rather than infer safety from product name alone.

Is special configuration required?

Palo Alto Networks says no special configuration is required for the vulnerability to exist on affected software. Exploitability still depends on network access to the relevant management web or dataplane interface.

Restricting management-interface access to trusted addresses can reduce risk, but it should not be treated as equivalent to upgrading to a fixed PAN-OS release because the vendor advisory also discusses dataplane-interface exposure.

Is CVE-2026-0310 actively exploited?

Palo Alto Networks currently says it is not aware of malicious exploitation of CVE-2026-0310. That is the current vendor state, not a guarantee that exploitation cannot occur later.

Because PA-Series hardware can face a root-code-execution consequence when the vulnerable path is reachable, administrators should base remediation on exposure and affected software state rather than wait for confirmed exploitation.

Which PAN-OS versions fix CVE-2026-0310?

The fix is branch-specific. Administrators should compare their exact running release against Palo Alto Networks’ current affected-and-fixed matrix rather than rely on one generic version number.

Examples confirmed in the current advisory and release documentation include:

  • PAN-OS 12.2: upgrade affected 12.2.0 through 12.2.2 deployments to 12.2.3 or later.
  • PAN-OS 12.1: fixed thresholds vary by minor branch and include fixed releases such as 12.1.4-h10, 12.1.7-h5 and 12.1.10.
  • PAN-OS 11.2, 11.1 and 10.2: Palo Alto Networks publishes branch-specific hotfix thresholds that must be checked against the exact installed release.

Do not extrapolate one fixed version across all branches. The safe verification method is to identify the exact product and PAN-OS build, then compare it directly with the current vendor matrix.

What should administrators do with unsupported PAN-OS versions?

Palo Alto Networks advises customers running unsupported PAN-OS versions to move to a supported release that contains the fix. An end-of-support deployment should therefore be treated as an upgrade or migration problem rather than assuming a new hotfix will be released for that branch.

What about Prisma Access and Cloud NGFW?

Palo Alto Networks treats Prisma Access and Cloud NGFW differently from PA-Series hardware in its advisory. The vendor rates these managed-service cases lower than the PA-Series hardware scenario and says affected managed customers will be upgraded during a scheduled maintenance cycle.

Customers that need an earlier managed-service upgrade should use Palo Alto Networks’ current support or account-management route. The exact tenant upgrade state cannot be inferred from the public advisory alone.

How can an administrator verify remediation?

Identify the product

Confirm whether the deployment is PA-Series, VM-Series, Panorama, Prisma Access or Cloud NGFW.

Record the exact release

Check the running PAN-OS version and hotfix level rather than relying on a major-version label.

Compare with the vendor matrix

Verify whether that exact branch is below Palo Alto Networks’ fixed threshold.

Apply the supported fix

Upgrade affected systems to the applicable fixed PAN-OS release or vendor-managed service state.

Verify the resulting state

Confirm that the running version is at or beyond the vendor’s fixed threshold and preserve that patch state in the security record.

Why PA-Series and VM-Series should not be treated the same

The vendor’s current consequence assessment is materially different. PA-Series hardware can face arbitrary code execution with root privileges, while the VM-Series impact is described as denial of service. A generic statement that every affected Palo Alto firewall can be remotely rooted would therefore overstate the evidence.

What happens next?

The most important developments to monitor are a Palo Alto Networks advisory revision, evidence of malicious exploitation, CISA Known Exploited Vulnerabilities status, new indicators of compromise or detection guidance, revised affected-version ranges, or changes to managed-service upgrade timing.

Those developments should update this same CVE-2026-0310 page while the reader’s core job remains verifying exposure and reaching a fixed software state.

Verification note

TPS reviewed Palo Alto Networks’ CVE-2026-0310 advisory and current PAN-OS release documentation, with current government and industry security advisories used for corroboration. The vulnerability, product-specific consequences and fixed-version guidance are confirmed; future exploitation, exposed-device counts, CVE-specific indicators and individual managed-service upgrade completion remain unresolved.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance for CVE-2026-0310. Palo Alto Networks confirms the vulnerability and fixed releases, but product-specific exposure, managed-service upgrade state and exploitation status can change. PA-Series, VM-Series, Panorama and managed cloud products do not all have identical impact. Administrators should verify their exact product, PAN-OS release and current Palo Alto Networks advisory before making consequential security changes.