Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0286

CVE-2026-0286 release notes and known issues

PAN-OS: Authenticated Command Injection in CLI

Scope: Cloud NGFW. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Cloud NGFW
  • PAN-OS
  • Prisma Access

Affected versions

  • None
  • < 12.1.4-h8, < 12.1.7-h2, < 12.1.8
  • < 11.2.4-h20, < 11.2.7-h18, < 11.2.10-h11, < 11.2.13
  • < 11.1.4-h35, < 11.1.6-h35, < 11.1.7-h8, < 11.1.10-h30, < 11.1.13-h9, < 11.1.16
  • < 10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8

Fixed versions or updates

  • All
  • >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
  • >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h11, >= 11.2.13
  • >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
  • >= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN-OS 11.2 11.2.11 through 11.2.12 Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h11 or 11.2.13 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later. PAN-OS 11.1 11.1.14 through 11.1.15 Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later. PAN-OS 10.2 10.2.17 through 10.2.18-h* Upgrade to 10.2.18-h8 or later. 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h9 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h23 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h39 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h36 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access No action needed.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

PAN-OS: Authenticated Command Injection in CLI

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source