Palo Alto Networks Warns of Critical PAN-OS Flaw Allowing Remote Code Execution

Last updated: September 14, 2026 Reading time: 4 minutes
Disclosure
Share
Palo Alto Networks Warns of Critical PAN-OS Flaw Allowing Remote Code Execution
  • Palo Alto Networks found a serious bug in its PAN-OS firewall software.
  • Hackers do not need a password to break in. They just need network access.
  • The company says no one has misused the flaw yet, but fixes are ready now.

Palo Alto Networks makes firewalls that many companies use to guard their networks. The company just found a dangerous flaw in its PAN-OS software.

This flaw could let a hacker take full control of certain firewalls. The scary part? The attacker does not need a password or any login details.

Inside the PAN-OS Security Flaw

Security teams track this bug as CVE-2026-0310. It lives inside a part of PAN-OS that reads XML data. Think of XML as a filing system computers use to organize information. When this part of the software gets confused, bad things can happen.

Palo Alto Networks shared the news on September 9. The company marked it as the most urgent type of warning it gives. Experts rate the danger as HIGH. On a scale up to 10, it scored 9.2 for risk.

Here is how an attack could work. A hacker only needs network access to the firewall. They could reach it through the management screen or the main traffic system. No password is needed. No click from a victim is needed either. The system just needs to receive the wrong kind of data.

Technicians call this bug an “out-of-bounds write.” That means the software tries to save data in a spot that is too small. It is like trying to stuff a big suitcase into a tiny closet. The suitcase spills out and messes up things nearby. In computer terms, this can crash the system or let attackers sneak in harmful commands.

Some Systems Face More Danger than Others

Not every affected device faces the same risk. Physical firewalls, called PA-Series hardware, face the worst outcome. A successful attack here could give hackers full “root” access. Root access means total control, like holding the master key to a building.

Virtual firewalls, called VM-Series, face a smaller threat. An attack there would likely crash the system instead. This is called a denial-of-service. It stops the firewall from working, but it does not hand over full control. Panorama, the tool that manages many firewalls at once, is also at risk. If an attacker breaks into Panorama, they could affect several devices at the same time.

Two other Palo Alto Networks products, Prisma Access and Cloud NGFW, face lower danger. Attackers would need a valid login to strike these systems. Outside access is also more limited for both tools. Because of this, Palo Alto Networks rates their risk as MEDIUM instead of HIGH.

Good news arrived alongside the warning too. According to Palo Alto Networks, no one has used this flaw in an attack yet. That means hackers have not exploited it in the real world, at least not that the company knows of. Even so, security teams should treat this as urgent. A known flaw with no active attacks can still turn into one fast, once details spread further online.

A recent Microsoft security update shows why organizations cannot afford to wait. The company fixed a record 974 security flaws, including two Windows vulnerabilities that attackers were already exploiting. This highlights how quickly serious vulnerabilities can move from disclosure to active attacks.

Fixes Are Already Out, Patch Now

Palo Alto Networks has already released updates that close this gap. Several versions received fixes, including PAN-OS 12.2.3 and 12.1.4-h10. Other patched versions include 12.1.7-h5, 12.1.10, and 11.2.4-h21. More fixes cover 11.2.7-h20, 11.2.10-h14, and 11.2.13-h2. The exact update needed depends on which version a company currently runs.

Palo Alto Networks also shared safety tips beyond just updating software. The company suggests limiting who can reach the management interface at all. One smart trick involves using a “jump box.” This is a single, tightly controlled computer that acts as the only gateway to sensitive systems. It adds an extra checkpoint before anyone reaches the firewall settings.

Government cyber teams have echoed the same warning. The Canadian Centre for Cyber Security posted an alert on September 10. The alert tells administrators to check Palo Alto Networks’ advisory and apply updates quickly. NHS England Digital gave similar advice to healthcare organizations that use the affected systems.

For any business running PA-Series firewalls or Panorama, the message is simple. Check which version your system uses right now. Update to a fixed version as soon as possible. Also review who can access your management interface from outside your network. Waiting too long could leave a wide-open door for attackers, even if no one has walked through it yet.

Companies that rely on Palo Alto Networks products should not treat this as routine maintenance. A flaw this severe, sitting on internet-facing hardware, deserves quick action. Patch first, then double-check your access settings after that.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts