A crafted XML request can root a Palo Alto firewall

Published

Palo Alto Networks has patched a flaw that lets an attacker with no account and no password send malformed XML to a firewall and run code on it as root. The company's advisory scores CVE-2026-0310 at 9.2 on its PA-Series hardware, the highest rating in this month's batch, and says Palo Alto is not aware of any malicious exploitation of the issue.

A firewall is the device that decides what gets in. This one can be given instructions by anything able to reach it.

One flaw an outsider can reach, three that need a foothold

CVE-2026-0310 is a buffer overflow in XML processing. Palo Alto says an unauthenticated attacker with network access can use it to cause a denial of service on VM-Series software firewalls, or to achieve "arbitrary code execution with root privileges" on PA-Series appliances. The score moves with the product: 9.2 for PA-Series, 8.7 for VM-Series, and 7.5 for Prisma Access and Cloud NGFW. Panorama, the console used to manage a fleet of firewalls centrally, is affected as well.

The other three flaws all require the attacker to be somewhere already. CVE-2026-0307, scored 5.9, is a set of local privilege escalation bugs in the GlobalProtect app, and Palo Alto's advisory says a local, non-administrative user can raise themselves to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux, with no special configuration required to be affected. CVE-2026-0308, scored 4.8, is a stored cross-site scripting flaw that lets an authenticated administrator store or execute a JavaScript payload through the PAN-OS web interface. CVE-2026-0309, scored 4.0, lets an authenticated administrator with command line access run commands as root, but only on a device configured with a Luna hardware security module.

Know which branch your firewalls are on

The fixed PAN-OS builds are 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 and 10.2.18-h10 or later, but the affected list runs across a long tail of maintenance branches, so the version an administrator actually needs depends on which branch a given device sits on. GlobalProtect app users need 6.3.3-h15, 6.2.8-h14 or 6.0.15 or later, and the iOS, Android and ChromeOS builds are listed as affected in all versions. Hong Kong's HKCERT, whose bulletin on 10 September collected the set, publishes the full version matrix alongside Palo Alto's own per-CVE pages.

Palo Alto's remote access software has drawn attention recently. In August the company fixed a separate flaw that let a rogue VPN gateway run code on the GlobalProtect clients connecting to it. Security appliances have been a steady target this year, and CISA added a Citrix NetScaler authentication bypass to its exploited catalog this week alongside a Cisco firewall management flaw that a Russian linked group and a ransomware crew were both using.

None of the four Palo Alto flaws is known to be under attack, and three of them need access an intruder would have to earn first. CVE-2026-0310 does not wait for that. A device placed at the perimeter is reachable by design, which is exactly what turns a parsing bug into a front door.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions