Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN884
_____________________________________________________________________

DATE                : 11/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): PAN-OS, Cloud NGFW, Prisma Access.
 
=====================================================================
https://security.paloaltonetworks.com/CVE-2026-0310
_____________________________________________________________________

CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing

Urgency HIGHEST
Severity 7.2 · HIGH

Exploit Maturity UNREPORTED
Response Effort MODERATE
Recovery USER
Value Density DIFFUSE
Attack Vector NETWORK
Attack Complexity HIGH
Attack Requirements NONE
Automatable NO
User Interaction NONE
Product Confidentiality HIGH
Product Integrity HIGH
Product Availability HIGH
Privileges Required NONE
Subsequent Confidentiality LOW
Subsequent Integrity LOW
Subsequent Availability NONE

Published 2026-09-09
Updated 2026-09-09
Discovered internally


Description

A buffer overflow vulnerability in the XML processing functionality of
Palo Alto Networks PAN-OS® software enables an unauthenticated attacker
with network access to the management web or dataplane interface to
cause a denial of service (DoS) condition on VM-Series firewalls or
execute arbitrary code with root privileges on the PA-Series firewalls.

The security risk posed by this issue is minimized when the management
interface is restricted to only trusted internal IP addresses according
to our recommended best practice deployment guidelines.

Panorama is impacted by this vulnerability.


Product Status
Versions	Affected	Unaffected
Cloud NGFW	All on AWS*
                All on Azure*
	                      None on AWS*
                              None on Azure*
PAN-OS 12.2	< 12.2.3
	                         >= 12.2.3
PAN-OS 12.1	< 12.1.4-h10
                < 12.1.7-h5
                < 12.1.10
	                       >= 12.1.4-h10
                               >= 12.1.7-h5
                               >= 12.1.10
PAN-OS 11.2	< 11.2.4-h21
                < 11.2.7-h20
                < 11.2.10-h14
                < 11.2.13-h2
	                       >= 11.2.4-h21
                               >= 11.2.7-h20
                               >= 11.2.10-h14
                               >= 11.2.13-h2
PAN-OS 11.1	< 11.1.4-h36
                < 11.1.6-h38
                < 11.1.7-h10
                < 11.1.10-h33
                < 11.1.13-h12
                < 11.1.16-h2
	                       >= 11.1.4-h36
                               >= 11.1.6-h38
                               >= 11.1.7-h10
                               >= 11.1.10-h33
                               >= 11.1.13-h12
                               >= 11.1.16-h2
PAN-OS 10.2	< 10.2.7-h37
                < 10.2.10-h40
                < 10.2.13-h24
                < 10.2.16-h10
                < 10.2.18-h10
	                       >= 10.2.7-h37
                               >= 10.2.10-h40
                               >= 10.2.13-h24
                               >= 10.2.16-h10
                               >= 10.2.18-h10
Prisma Access 12.1   < 12.1.7-h5*
                                      >= 12.1.7-h5*
Prisma Access 11.2   < 11.2.7-h20*
                                      >= 11.2.7-h20*
Prisma Access 10.2   < 10.2.10-h40*
                                      >= 10.2.10-h40*

* This is a medium severity vulnerability for Prisma Access and Cloud NGFW.
Please refer to the Severity section for impact details. Palo Alto Networks
Prisma Access and Cloud NGFW will upgrade all customers during the next
scheduled maintenance cycle. Customers who require an upgrade prior to
this cycle should contact Palo Alto Networks Support or their account
teams to schedule an on-demand software upgrade window.


Required Configuration for Exposure

No special configuration is required to be affected by this issue.

Severity: HIGH, Suggested Urgency: HIGHEST

The risk is highest for PA-Series hardware firewalls as there is a
risk of arbitrary code execution
HIGH - CVSS-BT: 7.2 /CVSS-B: 9.2 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)

The risk is lower for VM-Series firewalls, as the impact is limited
to a Denial of Service condition
MEDIUM - CVSS-BT: 6.6 /CVSS-B: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

The risk of exploitation is lower for Prisma Access and Cloud NGFW
as it requires an authenticated user and the external network access
is restricted.
MEDIUM - CVSS-BT: 4.8 /CVSS-B: 7.5 (CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

You can reduce the risk of exploitation by restricting access to a
jump box that is the only system allowed to access the management
interface.
MEDIUM - CVSS-BT: 5.2 /CVSS-B: 7.7 (CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)


Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this
issue.

Weakness Type and Impact

CWE-787 Out-of-bounds Write

CAPEC-100 Overflow Buffers


Solution

Version     Minor Version     	Suggested Solution

Cloud NGFW 		Customers who prefer to upgrade can work with
Palo Alto Networks support to schedule an on-demand software upgrade.

PAN-OS 12.2
	12.2.0 through 12.2.2 	Upgrade to 12.2.3 or later.

PAN-OS 12.1
	12.1.8 through 12.1.9 	Upgrade to 12.1.10 or later.
	12.1.5 through 12.1.7-h* 	Upgrade to 12.1.7-h5 or 12.1.10 or later.
	12.1.2 through 12.1.4-h* 	Upgrade to 12.1.4-h10 or 12.1.10 or later.

PAN-OS 11.2 	11.2.11 through 11.2.13-h* 	Upgrade to 11.2.13-h2 or later.
	11.2.8 through 11.2.10-h* 	Upgrade to 11.2.10-h14 or later.
	11.2.5 through 11.2.7-h* 	Upgrade to 11.2.7-h20 or later.
	11.2.0 through 11.2.4-h* 	Upgrade to 11.2.4-h21 or later.

PAN-OS 11.1
	11.1.14 through 11.1.16-h*
	Upgrade to 11.1.16-h2 or later.
	11.1.11 through 11.1.13-h* 	Upgrade to 11.1.13-h12 or later.
	11.1.8 through 11.1.10-h* 	Upgrade to 11.1.10-h33 or later.
	11.1.7 through 11.1.7-h* 	Upgrade to 11.1.7-h10 or later.
	11.1.5 through 11.1.6-h* 	Upgrade to 11.1.6-h38 or later.
	11.1.0 through 11.1.4-h* 	Upgrade to 11.1.4-h36 or later.

PAN-OS 10.2
	10.2.17 through
                       10.2.18-h* 	Upgrade to 10.2.18-h10 or later.
	10.2.14 through 10.2.16-h* 	Upgrade to 10.2.16-h10 or later.
	10.2.11 through 10.2.13-h* 	Upgrade to 10.2.13-h24 or later.
	10.2.8 through 10.2.10-h* 	Upgrade to 10.2.10-h40 or later.
	10.2.0 through 10.2.7-h* 	Upgrade to 10.2.7-h37 or later.

All older
unsupported
PAN-OS versions	 	Upgrade to a supported fixed version.

Prisma Access 12.1   	12.1.2 through 12.1.*	Upgrade to 12.1.7-h5 or later.

Prisma Access 11.2  	11.2.0 through 11.2*	Upgrade to 11.2.7-h20 or later.

Prisma Access 10.2	10.2.0 through 10.2.*	Upgrade to 10.2.10-h40 or later.

* See the note under Product Status for information regarding Prisma
Access and Cloud NGFW upgrades.


Workarounds and Mitigations

No known workarounds exist for this issue.


Acknowledgments
Palo Alto Networks thanks our internal security research teams
for discovering and reporting this issue.


CPEs

cpe:2.3:o:palo_alto_networks:pan-os:12.2.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:h3:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:h2:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:h1:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:-:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.4:h9:*:*:*:*:*:*
Show More

CPE Applicability

        cpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:AWS:*:* is vulnerable from (including)all
        ORcpe:2.3:o:palo_alto_networks:cloud_ngfw:*:*:*:*:*:Azure:*:* is vulnerable from (including)all
    or
        cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)12.2.0 and up to (excluding)12.2.3
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)12.1.0 and up to (excluding)12.1.10
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)12.1.7 and up to (excluding)12.1.7-h5
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)12.1.4 and up to (excluding)12.1.4-h10
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.13 and up to (excluding)11.2.13-h2
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.10 and up to (excluding)11.2.10-h14
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.7 and up to (excluding)11.2.7-h20
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.4 and up to (excluding)11.2.4-h21
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.16 and up to (excluding)11.1.16-h2
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.13 and up to (excluding)11.1.13-h12
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.10 and up to (excluding)11.1.10-h33
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.7 and up to (excluding)11.1.7-h10
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.6 and up to (excluding)11.1.6-h38
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.4 and up to (excluding)11.1.4-h36
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.18 and up to (excluding)10.2.18-h10
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.16 and up to (excluding)10.2.16-h10
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.13 and up to (excluding)10.2.13-h24
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.10 and up to (excluding)10.2.10-h40
        ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.7 and up to (excluding)10.2.7-h37
    or
        cpe:2.3:o:palo_alto_networks:prisma_access:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.7 and up to (excluding)11.2.7-h20
        ORcpe:2.3:o:palo_alto_networks:prisma_access:*:*:*:*:*:*:*:* is vulnerable from (including)10.2.10 and up to (excluding)10.2.10-h40


Timeline

2026-09-09    Initial Publication


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




