Skip to content
Auto-CTI
Back to today
NEW CRITICAL A3

CVE-2026-0310: Buffer Overflow in Palo Alto Networks PAN-OS XML Processing Enables DoS and Remote Code Execution

A NVD · · CVE-2026-0310

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

Critical vulnerability in PAN-OS XML processing enables unauthenticated access to management and dataplane interfaces, with root-level code execution on PA-Series; Panorama affected.

Description

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial-of-service condition on VM-Series firewalls or execute arbitrary code with root privileges on PA-Series firewalls. The Panorama management system is also affected. The vulnerability exists in core packet processing and impacts both virtual and physical appliances, with consequences varying by hardware type (DoS vs. RCE).

Risk score

50
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
45.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC