A Malformed XML Request Can Give an Attacker Root on Palo Alto Hardware Firewalls
An unauthenticated XML request can do more than crash an affected Palo Alto Networks firewall. On PA-Series hardware, it can lead to arbitrary code execution as root. The same vulnerability is limited to denial of service on VM-Series firewalls, but Panorama is also affected, no special configuration is required and no workaround exists.
Palo Alto Networks disclosed CVE-2026-0310 on 9 September 2026 and assigned it its highest suggested urgency. The company says it is not aware of malicious exploitation. The PA-Series root-code-execution scenario has high attack complexity. The VM-Series denial-of-service scenario has low attack complexity. Prisma Access and Cloud NGFW use a separate scenario that requires an authenticated user, adjacent network access and high attack complexity.
Those qualifications matter. They should prevent exaggerated claims, not delay remediation. The vulnerable XML-processing code is reachable over the network through the management web or dataplane interface, requires no account and can cross directly into root-level execution on physical firewalls.
The platform decides whether the outcome is a crash or root
CVE-2026-0310 is an out-of-bounds write in PAN-OS XML processing. An unauthenticated attacker with network access to an affected interface can supply malformed XML that corrupts memory.
Palo Alto Networks describes different consequences by deployment type:
- PA-Series hardware firewalls: arbitrary code execution with root privileges is possible.
- VM-Series firewalls: the impact is limited to a denial-of-service condition.
- Panorama: the management platform is affected, but the vendor does not assign it the same explicit root-execution or denial-of-service impact split used for PA-Series and VM-Series. Either specific outcome should not be inferred from the published description.
- Prisma Access and Cloud NGFW: affected, but Palo Alto Networks rates the issue medium in these services because exploitation requires an authenticated user and external network access is restricted.
The distinction is operationally important. A virtual firewall that restarts can still interrupt critical connectivity. A physical firewall that gives an attacker root is a potential security-boundary failure, with consequences for policy enforcement, traffic visibility, credentials and trusted network paths.
The vendor rates the PA-Series case High at CVSS-BT 7.2 and CVSS base 9.2. It rates VM-Series impact Medium at CVSS-BT 6.6 and CVSS base 8.7. The higher base score does not contradict the High label: Palo Alto Networks uses the threat-adjusted score, including the current absence of reported exploitation, for the displayed severity.
No special feature needs to be switched on
Palo Alto Networks says no special configuration is required for exposure. The attack still depends on network reachability to the management web or dataplane interface. For PA-Series root execution, the vendor rates attack complexity as high. For VM-Series denial of service, it rates attack complexity as low. The hosted Prisma Access and Cloud NGFW scenario is different again: it requires an authenticated user, adjacent network access and high attack complexity.
Restricting the management interface to a dedicated jump box reduces one route. It does not remove exposure through a reachable dataplane interface and is not a substitute for installing a fixed release.
This is also why an inventory should include Panorama and less visible appliances. A team may protect the public management interface while overlooking an internally reachable management server, a lab firewall, an HA peer or a virtual appliance whose availability is essential to network recovery.
Fixed PAN-OS releases
The correct target depends on the currently installed minor branch. Palo Alto Networks provides the following upgrade matrix:
| PAN-OS branch | Affected minor versions | Upgrade target |
|---|---|---|
| 12.2 | 12.2.0 through 12.2.2 | 12.2.3 or later |
| 12.1 | 12.1.8 through 12.1.9 | 12.1.10 or later |
| 12.1 | 12.1.5 through 12.1.7-h* | 12.1.7-h5 or 12.1.10 or later |
| 12.1 | 12.1.2 through 12.1.4-h* | 12.1.4-h10 or 12.1.10 or later |
| 11.2 | 11.2.11 through 11.2.13-h* | 11.2.13-h2 or later |
| 11.2 | 11.2.8 through 11.2.10-h* | 11.2.10-h14 or later |
| 11.2 | 11.2.5 through 11.2.7-h* | 11.2.7-h20 or later |
| 11.2 | 11.2.0 through 11.2.4-h* | 11.2.4-h21 or later |
| 11.1 | 11.1.14 through 11.1.16-h* | 11.1.16-h2 or later |
| 11.1 | 11.1.11 through 11.1.13-h* | 11.1.13-h12 or later |
| 11.1 | 11.1.8 through 11.1.10-h* | 11.1.10-h33 or later |
| 11.1 | 11.1.7 through 11.1.7-h* | 11.1.7-h10 or later |
| 11.1 | 11.1.5 through 11.1.6-h* | 11.1.6-h38 or later |
| 11.1 | 11.1.0 through 11.1.4-h* | 11.1.4-h36 or later |
| 10.2 | 10.2.17 through 10.2.18-h* | 10.2.18-h10 or later |
| 10.2 | 10.2.14 through 10.2.16-h* | 10.2.16-h10 or later |
| 10.2 | 10.2.11 through 10.2.13-h* | 10.2.13-h24 or later |
| 10.2 | 10.2.8 through 10.2.10-h* | 10.2.10-h40 or later |
| 10.2 | 10.2.0 through 10.2.7-h* | 10.2.7-h37 or later |
| Older unsupported releases | All | Move to a supported fixed release |
Palo Alto Networks gives these hosted-service minimums:
| Service branch | Fixed level |
|---|---|
| Prisma Access 12.1 | 12.1.7-h5 or later |
| Prisma Access 11.2 | 11.2.7-h20 or later |
| Prisma Access 10.2 | 10.2.10-h40 or later |
The vendor says it will upgrade Prisma Access and Cloud NGFW customers during the next scheduled maintenance cycle. Customers that need an earlier window can contact Palo Alto Networks Support or their account team.
What defenders should do now
- Identify the exact platform and branch. Separate PA-Series, VM-Series, Panorama, Prisma Access and Cloud NGFW. The impact and upgrade process are not identical.
- Map interface reachability. Record which systems can reach management web interfaces and which dataplane services are externally or internally exposed.
- Upgrade to the branch-specific fixed level. Use Palo Alto Networks' matrix rather than assuming the newest hotfix on an old minor release contains the correction.
- Place management access behind a jump box. Permit only dedicated administrative sources and remove direct internet access. Treat this as exposure reduction, not remediation.
- Plan for HA and Panorama dependencies. Validate peer compatibility, management reachability and rollback procedures before the maintenance window.
- Monitor for abnormal restarts and process behaviour. Unexpected firewall crashes, repeated management-interface requests, new administrative changes or unexplained outbound traffic require investigation.
- Treat suspicious PA-Series activity as a possible root compromise. Preserve logs and volatile evidence, rotate credentials available to the appliance and assess whether a clean rebuild is required.
No exploitation report does not mean low consequence
Palo Alto Networks says it has not observed malicious exploitation of CVE-2026-0310. BlackTree found no credible public proof of concept in its review on 11 September 2026. Defenders should keep those dated findings separate from speculative scanning claims or unverified code repositories.
The reason to act quickly is the consequence if exploitation succeeds. Firewalls occupy a privileged position: they inspect, allow and deny traffic while connecting networks that are deliberately separated. Root access on that boundary can undermine assumptions far beyond the appliance itself.
BlackTree previously covered another PAN-OS path in which an authentication portal became a route to root. The recurring lesson is not that every Palo Alto Networks disclosure is automatically an emergency. It is that unauthenticated memory corruption in a security boundary deserves priority before exploit maturity changes.
For this flaw, the practical sequence is straightforward: reduce management exposure now, identify every affected platform, and install the fixed release. The network restriction buys margin. The upgrade closes the vulnerability.
Sources
- Palo Alto Networks advisory for CVE-2026-0310, published and updated 9 September 2026, no time provided.
- Canadian Centre for Cyber Security advisory AV26-905, published 10 September 2026, no time provided.
- CVE Program record for CVE-2026-0310.


