CVE-2026-0310: Buffer Overflow in Palo Alto Networks PAN-OS XML Processing Enables DoS and Remote Code Execution
A NVD · · CVE-2026-0310
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- EPSS
- 0%
Key insight
Critical vulnerability in PAN-OS XML processing enables unauthenticated access to management and dataplane interfaces, with root-level code execution on PA-Series; Panorama affected.
Description
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial-of-service condition on VM-Series firewalls or execute arbitrary code with root privileges on PA-Series firewalls. The Panorama management system is also affected. The vulnerability exists in core packet processing and impacts both virtual and physical appliances, with consequences varying by hardware type (DoS vs. RCE).
Risk score
- cvss base
- 45.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 45.00
- industry weight
- 1.10
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational