VORANT. Threat Intelligence Sign in Get the full feed

Palo Alto PAN-OS XML Buffer Overflow Patched

routine vulnerability technologyinfrastructure

NCSC-NL advisory: a PAN-OS XML parsing buffer overflow lets unauthenticated attackers crash VM-Series or gain root code execution on PA-Series firewalls.

NCSC-NL published an advisory covering CVE-2026-0310, a buffer overflow in the XML-processing functionality of Palo Alto Networks PAN-OS software. The flaw affects VM-Series and PA-Series firewalls as well as Panorama management software. Improper handling of XML input leads to memory corruption, which unauthenticated network-based attackers can exploit to cause a denial-of-service condition on VM-Series firewalls, or achieve arbitrary code execution with root privileges on PA-Series firewalls, potentially resulting in full system compromise.

No indication of active exploitation in the wild is mentioned in the advisory. Palo Alto Networks has released updates addressing the vulnerability. Given that no authentication is required and the affected products are commonly deployed as network perimeter security devices, defenders operating VM-Series, PA-Series, or Panorama should prioritize applying the vendor patches and review referenced advisories for affected version details.

Mentioned in this report

Vulnerabilities CVE-2026-0310

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0369.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free