- Palo Alto Networks found a serious bug in its PAN-OS firewall software.
- Hackers do not need a password to break in. They just need network access.
- The company says no one has misused the flaw yet, but fixes are ready now.
Palo Alto Networks makes firewalls that many companies use to guard their networks. The company just found a dangerous flaw in its PAN-OS software.
This flaw could let a hacker take full control of certain firewalls. The scary part? The attacker does not need a password or any login details.
Inside the PAN-OS Security Flaw
Security teams track this bug as CVE-2026-0310. It lives inside a part of PAN-OS that reads XML data. Think of XML as a filing system computers use to organize information. When this part of the software gets confused, bad things can happen.
Palo Alto Networks shared the news on September 9. The company marked it as the most urgent type of warning it gives. Experts rate the danger as HIGH. On a scale up to 10, it scored 9.2 for risk.
Here is how an attack could work. A hacker only needs network access to the firewall. They could reach it through the management screen or the main traffic system. No password is needed. No click from a victim is needed either. The system just needs to receive the wrong kind of data.
Technicians call this bug an “out-of-bounds write.” That means the software tries to save data in a spot that is too small. It is like trying to stuff a big suitcase into a tiny closet. The suitcase spills out and messes up things nearby. In computer terms, this can crash the system or let attackers sneak in harmful commands.
Some Systems Face More Danger than Others
Not every affected device faces the same risk. Physical firewalls, called PA-Series hardware, face the worst outcome. A successful attack here could give hackers full “root” access. Root access means total control, like holding the master key to a building.
Virtual firewalls, called VM-Series, face a smaller threat. An attack there would likely crash the system instead. This is called a denial-of-service. It stops the firewall from working, but it does not hand over full control. Panorama, the tool that manages many firewalls at once, is also at risk. If an attacker breaks into Panorama, they could affect several devices at the same time.
Two other Palo Alto Networks products, Prisma Access and Cloud NGFW, face lower danger. Attackers would need a valid login to strike these systems. Outside access is also more limited for both tools. Because of this, Palo Alto Networks rates their risk as MEDIUM instead of HIGH.
Good news arrived alongside the warning too. According to Palo Alto Networks, no one has used this flaw in an attack yet. That means hackers have not exploited it in the real world, at least not that the company knows of. Even so, security teams should treat this as urgent. A known flaw with no active attacks can still turn into one fast, once details spread further online.
A recent Microsoft security update shows why organizations cannot afford to wait. The company fixed a record 974 security flaws, including two Windows vulnerabilities that attackers were already exploiting. This highlights how quickly serious vulnerabilities can move from disclosure to active attacks.
Fixes Are Already Out, Patch Now
Palo Alto Networks has already released updates that close this gap. Several versions received fixes, including PAN-OS 12.2.3 and 12.1.4-h10. Other patched versions include 12.1.7-h5, 12.1.10, and 11.2.4-h21. More fixes cover 11.2.7-h20, 11.2.10-h14, and 11.2.13-h2. The exact update needed depends on which version a company currently runs.
Palo Alto Networks also shared safety tips beyond just updating software. The company suggests limiting who can reach the management interface at all. One smart trick involves using a “jump box.” This is a single, tightly controlled computer that acts as the only gateway to sensitive systems. It adds an extra checkpoint before anyone reaches the firewall settings.
Government cyber teams have echoed the same warning. The Canadian Centre for Cyber Security posted an alert on September 10. The alert tells administrators to check Palo Alto Networks’ advisory and apply updates quickly. NHS England Digital gave similar advice to healthcare organizations that use the affected systems.
For any business running PA-Series firewalls or Panorama, the message is simple. Check which version your system uses right now. Update to a fixed version as soon as possible. Also review who can access your management interface from outside your network. Waiting too long could leave a wide-open door for attackers, even if no one has walked through it yet.
Companies that rely on Palo Alto Networks products should not treat this as routine maintenance. A flaw this severe, sitting on internet-facing hardware, deserves quick action. Patch first, then double-check your access settings after that.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
New Mantax Otax Android Malware Combines Ransomware, Spyware and Harassment
Mantax Otax is an Android malware strain operated by Indonesian threat actors that fuses file encryp...
Hacker Claims 600,000 Tax Records Stolen From Colombia’s Cali Government
A threat actor claims to have accessed a database from the Office of the Mayor of Santiago de Cali c...
Microsoft Fixes Record 974 Security Flaws as Two Windows Bugs Face Active Attacks
Microsoft fixed 974 security flaws this Patch Tuesday, its biggest release ever. Two Windows bugs ar...
ChatGPT Security Flaw Lets Hidden Prompts Exfiltrate Gmail Data Across Accounts
A single hidden instruction inside a ChatGPT chat could quietly hand a stranger access to a userR...
Australia Moves to Boost Social Media Privacy With Algorithm Opt-Out
Australia’s government may let users turn off personalized recommendation algorithms. People c...
Hackers Abuse Signed Node.js to Hide Malware from Antivirus Tools
Attackers have utilized the signed Node.js binary to launch malicious JavaScript code, enabling payl...