Palo Alto PAN-OS XML Buffer Overflow Patched
NCSC-NL advisory: a PAN-OS XML parsing buffer overflow lets unauthenticated attackers crash VM-Series or gain root code execution on PA-Series firewalls.
NCSC-NL published an advisory covering CVE-2026-0310, a buffer overflow in the XML-processing functionality of Palo Alto Networks PAN-OS software. The flaw affects VM-Series and PA-Series firewalls as well as Panorama management software. Improper handling of XML input leads to memory corruption, which unauthenticated network-based attackers can exploit to cause a denial-of-service condition on VM-Series firewalls, or achieve arbitrary code execution with root privileges on PA-Series firewalls, potentially resulting in full system compromise.
No indication of active exploitation in the wild is mentioned in the advisory. Palo Alto Networks has released updates addressing the vulnerability. Given that no authentication is required and the affected products are commonly deployed as network perimeter security devices, defenders operating VM-Series, PA-Series, or Panorama should prioritize applying the vendor patches and review referenced advisories for affected version details.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0369.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free