CVE-2026-0309Medium· 4.0▾ SunlitA command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.4%
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM).
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
cloud_ngfwPAN-OS >= 12.2.0 < 12.2.3PAN-OS >= 12.1.0 < 12.1.4-h10PAN-OS >= 11.2.0 < 11.2.4-h21PAN-OS >= 11.1.0 < 11.1.4-h36PAN-OS >= 10.2.0 < 10.2.7-h37prisma_accessVersion Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 12.2
12.2.0 through 12.2.2
Upgrade to 12.2.3 or later.
PAN-OS 12.1
12.1.8 through 12.1.9
Upgrade to 12.1.10 or later.
12.1.5 through 12.1.7-h*
Upgrade to 12.1.7-h5 or 12.1.10 or later.
12.1.2 through 12.1.4-h*
Upgrade to 12.1.4-h10 or 12.1.10 or later.
PAN-OS 11.2
11.2.11 through 11.2.13-h*
Upgrade to 11.2.13-h2 or later.
11.2.8 through 11.2.10-h*
Upgrade to 11.2.10-h14 or later.
11.2.5 through 11.2.7-h*
Upgrade to 11.2.7-h20 or later.
11.2.0 through 11.2.4-h*
Upgrade to 11.2.4-h21 or later.
PAN-OS 11.1
11.1.14 through 11.1.16-h*
Upgrade or 11.1.16-h2 or later.
11.1.11 through 11.1.13-h*
Upgrade to 11.1.13-h12 or later.
11.1.8 through 11.1.10-h*
Upgrade to 11.1.10-h33 or later.
11.1.7 through 11.1.7-h*
Upgrade to 11.1.7-h10 or later.
11.1.5 through 11.1.6-h*
Upgrade to 11.1.6-h38 or later.
11.1.0 through 11.1.4-h*
Upgrade to 11.1.4-h36 or later.
PAN-OS 10.2
10.2.17 through
10.2.18-h* Upgrade to 10.2.18-h10 or later.
10.2.14 through 10.2.16-h*
Upgrade to 10.2.16-h10 or later.
10.2.11 through 10.2.13-h*
Upgrade to 10.2.13-h24 or later.
10.2.8 through 10.2.10-h*
Upgrade to 10.2.10-h40 or later.
10.2.0 through 10.2.7-h*
Upgrade to 10.2.7-h37 or later.
All older
unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access No action needed.
No known workarounds exist for this issue.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0310High· 7.2A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …
CVE-2026-0302Low· 1.1An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
CVE-2026-0308Low· 1.1A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface
CVE-2026-0303Low· 2.4A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
CVE-2026-0304Medium· 4.8A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
CVE-2026-0307Medium· 5.9GlobalProtect App: Local Privilege Escalation Vulnerabilities