Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0308

CVE-2026-0308 release notes and known issues

PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Scope: Cloud NGFW. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Cloud NGFW
  • PAN-OS
  • Prisma Access

Affected versions

  • None
  • < 12.1.10
  • < 11.2.13-h2
  • < 11.1.16-h2

Fixed versions or updates

  • All
  • >= 12.1.10
  • >= 11.2.13-h2
  • >= 11.1.16-h2

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.2 No action needed. PAN-OS 12.1 12.1.2 through 12.1.9 Upgrade to 12.1.10 or later. PAN-OS 11.2 11.2.0 through 11.2.13 Upgrade to 11.2.13-h2 or later. PAN-OS 11.1 11.1.0 through 11.1.16 Upgrade to 11.1.16-h2 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access No action needed.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source