Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls.
Tracked as CVE-2026-0310, the flaw exists in XML processing, and the vendor has assigned it the highest suggested urgency. The vulnerability is a buffer overflow, classified as CWE-787 (out-of-bounds write).
An attacker with network access to a vulnerable management web interface or dataplane interface could send specially crafted XML data to trigger the issue.
On PA-Series appliances, successful exploitation may lead to arbitrary code execution as the root user, giving an attacker complete control over the firewall operating environment. Root-level code execution on an enterprise perimeter firewall presents a serious security risk.
A threat actor could potentially alter security policies, inspect or redirect network traffic, deploy persistence mechanisms, steal configuration data, or use the compromised device as a foothold for attacks against internal systems.
Palo Alto PAN-OS Vulnerability
The issue does not require authentication or user interaction, although exploitation has been rated as high complexity. Palo Alto Networks assigned CVE-2026-0310 a CVSS-BT score of 7.2 and a CVSS-B base score of 9.2 for affected PA-Series firewalls.
The vendor noted that the practical risk is greatest for physical firewall appliances because the flaw can result in root-level remote code execution. The impact differs across Palo Alto Networks products. On vulnerable VM-Series firewalls, exploitation is limited to a denial-of-service condition rather than code execution.
A successful attack could crash or disrupt the affected virtual firewall, affecting traffic inspection and availability. Prisma Access and Cloud NGFW environments are also affected.
However, Palo Alto Networks considers the risk lower because exploitation requires an authenticated user and external network access is more restricted.
Affected PAN-OS releases include versions before 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10, depending on the release branch. Numerous maintenance builds across the 10.2, 11.1, 11.2, and 12.1 branches are also vulnerable.
Organizations should upgrade immediately to the appropriate fixed release. Palo Alto Networks recommends PAN-OS 12.2.3 or later for the 12.2 branch.
No workaround is available. However, organizations can reduce exposure by ensuring that firewall management interfaces are not reachable from untrusted networks.
Palo Alto Networks recommends restricting management access to trusted internal IP addresses and, where possible, allowing administration only through a dedicated jump box. The vendor said it discovered CVE-2026-0310 internally and, as of September 9, 2026, is not aware of malicious exploitation in the wild.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User appeared first on Cyber Security News.
