# Palo Alto PAN-OS XML Buffer Overflow Patched

Published: 2026-09-15 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/3e20d914-01a8-5a32-9474-9cbea5de9a7a/palo-alto-pan-os-xml-buffer-overflow-patched

> NCSC-NL advisory: a PAN-OS XML parsing buffer overflow lets unauthenticated attackers crash VM-Series or gain root code execution on PA-Series firewalls.

NCSC-NL published an advisory covering CVE-2026-0310, a buffer overflow in the XML-processing functionality of Palo Alto Networks PAN-OS software. The flaw affects VM-Series and PA-Series firewalls as well as Panorama management software. Improper handling of XML input leads to memory corruption, which unauthenticated network-based attackers can exploit to cause a denial-of-service condition on VM-Series firewalls, or achieve arbitrary code execution with root privileges on PA-Series firewalls, potentially resulting in full system compromise.

No indication of active exploitation in the wild is mentioned in the advisory. Palo Alto Networks has released updates addressing the vulnerability. Given that no authentication is required and the affected products are commonly deployed as network perimeter security devices, defenders operating VM-Series, PA-Series, or Panorama should prioritize applying the vendor patches and review referenced advisories for affected version details.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0310

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0369.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3e20d914-01a8-5a32-9474-9cbea5de9a7a/palo-alto-pan-os-xml-buffer-overflow-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
