Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0310

CVE-2026-0310 release notes and known issues

PAN-OS: Buffer Overflow Vulnerability via XML Processing

Scope: Cloud NGFW. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. Panorama is impacted by this vulnerability.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Cloud NGFW
  • PAN-OS
  • Prisma Access

Affected versions

  • All on AWS*, All on Azure*
  • < 12.2.3
  • < 12.1.4-h10, < 12.1.7-h5, < 12.1.10
  • < 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2
  • < 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2
  • < 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10
  • < 12.1.7-h5*
  • < 11.2.7-h20*
  • < 10.2.10-h40*

Fixed versions or updates

  • None on AWS*, None on Azure*
  • >= 12.2.3
  • >= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10
  • >= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2
  • >= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2
  • >= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10
  • >= 12.1.7-h5*
  • >= 11.2.7-h20*
  • >= 10.2.10-h40*

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2.3 or later. PAN-OS 12.1 12.1.8 through 12.1.9 Upgrade to 12.1.10 or later. 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h5 or 12.1.10 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h10 or 12.1.10 or later. PAN-OS 11.2 11.2.11 through 11.2.13-h* Upgrade to 11.2.13-h2 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h14 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h20 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h21 or later. PAN-OS 11.1 11.1.14 through 11.1.16-h* Upgrade to 11.1.16-h2 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h12 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h33 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h10 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h38 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h36 or later. PAN-OS 10.2 10.2.17 through Upgrade to 10.2.18-h10 or later. 10.2.18-h* 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h10 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h24 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h40 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h37 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 12.1 12.1.2 through 12.1.* Upgrade to 12.1.7-h5 or later. Prisma Access 11.2 11.2.0 through 11.2* Upgrade to 11.2.7-h20 or later. Prisma Access 10.2 10.2.0 through 10.2.* Upgrade to 10.2.10-h40 or later. * See the note under Product Status for information regarding Prisma Access and Cloud NGFW upgrades.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

PAN-OS: Buffer Overflow Vulnerability via XML Processing

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source