synced 5 MIN AGO
01 Record

CVE-2026-0310

PAN-OS: Buffer Overflow Vulnerability via XML Processing

HighPUBLISHEDCNA: palo_alto
CNA base score7.2 CVSS v4.0CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red

02 Description

PAN-OS: Buffer Overflow Vulnerability via XML Processing

03 Exploitation and scoring

Exploitation
Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
SSVC decision
  • ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
  • AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
  • Technical ImpacttotalSuccessful exploitation gives total control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.
EPSS probability
0.34% probability of exploitation activity in the next 30 days.
EPSS percentile
Ranks above 26.8% of scored records. A rank, not a probability.
NVD base score
7.2 (CVSS v4.0), scored by the NVD independently of the CNA.
NVD CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red
NVD analysis status
Awaiting Analysis. NVD last modified this record on 2026-09-11.
Red Hat severity
No Red Hat rating. Red Hat rates the CVEs that affect its products.

Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.

04 Metadata

Published
2026-09-10 05:21Z1 DAY AGO
Last updated
2026-09-11 03:56Z14 HR AGO
Reserved
2025-11-03
Assigning CNA
palo_alto
Record state
PUBLISHED
Severity
High (CVSS 7.2)
CNA CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red
Weaknesses
Data version
5.2
Document digest
ab3e947558fdebcf56ebf5569741b8e7a5de52282fb2a52ba6dc9f393709b416

05 Affected products

VendorProductVersionsPlatforms
Palo Alto NetworksCloud NGFWAllAWS, Azure
Palo Alto NetworksPAN-OS12.2.0 to < 12.2.3, 12.1.0 to < 12.1.4-h10, 11.2.0 to < 11.2.4-h21, 11.1.0 to < 11.1.4-h36, 10.2.0 to < 10.2.7-h37
Palo Alto NetworksPrisma Access11.2.0 to < 11.2.4-h21, 10.2.0 to < 10.2.7-h37

06 References

07 Remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12.2 12.2.0 through 12.2.2 Upgrade to 12.2.3 or later. PAN-OS 12.1 12.1.8 through 12.1.9 Upgrade to 12.1.10 or later. 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h5 or 12.1.10 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h10 or 12.1.10 or later. PAN-OS 11.2 11.2.11 through 11.2.13-h* Upgrade to 11.2.13-h2 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h14 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h20 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h21 or later. PAN-OS 11.1 11.1.14 through 11.1.16-h* Upgrade to 11.1.16-h2 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h12 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h33 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h10 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h38 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h36 or later. PAN-OS 10.2 10.2.17 through Upgrade to 10.2.18-h10 or later. 10.2.18-h* 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h10 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h24 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h40 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h37 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 12.1 12.1.2 through 12.1.* Upgrade to 12.1.7-h5 or later. Prisma