CVE-2026-0310Patch

MEDIUM

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

5.8/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 24 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 14 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 8 mentions (2026-09-10); latest day: 4
  • 24 total mentions across 8 days

Deep dive

Activity timeline24 mentions / 8d
02468Mentions · 2026-06-21: 1Mentions · 2026-09-09: 4Mentions · 2026-09-10: 8Mentions · 2026-09-11: 2Mentions · 2026-09-12: 2Mentions · 2026-09-13: 1Mentions · 2026-09-16: 2Mentions · 2026-09-17: 4PoC Mentioned / Linked · 2026-09-10: 1Active Exploitation · 2026-09-09: 1Active Exploitation · 2026-09-11: 1Patch / Workaround · 2026-09-09: 3Patch / Workaround · 2026-09-10: 7Patch / Workaround · 2026-09-11: 1Patch / Workaround · 2026-09-12: 1Patch / Workaround · 2026-09-13: 1Technical Details · 2026-09-09: 2Technical Details · 2026-09-10: 8Technical Details · 2026-09-11: 1Technical Details · 2026-09-12: 2Technical Details · 2026-09-13: 106-2109-0909-1009-1109-1209-1309-1609-17
Signal classification4 categories
Patch
1161.1%
Disclosure
422.2%
General
211.1%
Active Exploitation
15.6%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-06-211
Disclosure1
2026-09-094
General1Patch3
2026-09-108
Disclosure1General1Patch6
2026-09-112
Active Exploitation1Patch1
2026-09-122
Disclosure1Patch1
2026-09-131
Disclosure1
Full discourse20 posts
  • Dark Web Intelligence@DailyDarkWeb
    Patch

    🚨 PALO ALTO NETWORKS WARNS OF PAN-OS FLAW ALLOWING UNAUTHENTICATED ROOT CODE EXECUTION Palo Alto Networks has disclosed CVE-2026-0310, a high-severity buffer overflow vulnerability affecting PAN-OS firewalls and Panorama. The vulnerability exists in PAN-OS XML processing functionality. On vulnerable PA-Series hardware firewalls, an UNAUTHENTICATED attacker with network access to the management web or dataplane interface could exploit the flaw to execute arbitrary code with ROOT privileges. Key details: * CVE: CVE-2026-0310 * Severity: HIGH * Palo Alto urgency: HIGHEST * CVSS-BT: 7.2 * CVSS Base: 9.2 * Attack vector: Network * Privileges required: NONE * User interaction: NONE * Weakness: CWE-787 Out-of-bounds Write * Panorama is also impacted * No special configuration is required for exposure * No known workaround exists Impact differs by platform. PA-Series hardware: → Arbitrary code execution with root privileges VM-Series: → Denial of Service Prisma Access / Cloud NGFW: → Lower exploitation risk and MEDIUM severity under their applicable conditions Palo Alto Networks has released fixed PAN-OS versions and recommends upgrading affected systems. ⚠️ IMPORTANT: There is currently NO evidence of active exploitation. Palo Alto Networks explicitly states that it is not aware of malicious exploitation of CVE-2026-0310. So this should currently be treated as a high-priority patching issue, NOT an actively exploited zero-day. ⚠️ Analyst Note: An unauthenticated root-RCE path against perimeter security infrastructure deserves attention even before exploitation is observed. Edge devices sit at an unusually valuable trust boundary. Firewall compromise → Root execution → Security-device control → Potential credential/configuration exposure → Internal-network access Organizations operating affected PA-Series firewalls should prioritize the fixed PAN-OS releases and restrict management-interface access wherever possible. Official Palo Alto Networks advisory: https://security.paloaltonetworks.com/CVE-2026-0310 #DDW #PaloAltoNetworks #PANOS #CVE #CyberSecurity

    Post summary

    Palo Alto Networks disclosed CVE‑2026‑0310, a high‑severity out‑of‑bounds write that allows unauthenticated root code execution on PAN‑OS firewalls, released patches, and reported no evidence of active exploitation.

    35141696220.7K
    204.4K followersView on X
  • FOFA@fofabot

    ⚠️⚠️ CVE-2026-0310 (CVSS 9.2): Pre-auth XML buffer overflow in PAN-OS -> root-level RCE on internet-exposed PA-Series firewall management interfaces. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJQYWxvLUFsdG8tcGFuLW9zIg== 🎯40.8K+ internet-facing PAN-OS management surfaces are found on http://en.fofa.info in the past year. FOFA Query: app="Palo-Alto-pan-os" 🔖Refer: https://security.paloaltonetworks.com/CVE-2026-0310 #OSINT #FOFA #CyberSecurity #Vulnerability

    09044244.3K
    14.8K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Palo Alto Networksは、PAN-OSのXML処理に認証不要で悪用可能なbuffer overflow脆弱性「CVE-2026-0310」があると公表した。PA-Seriesではroot権限で任意コード実行につながる。 問題はCWE-787に分類されるout-of-bounds writeで、管理Webインターフェースとdataplaneの双方に影響する。特別な設定や利用者操作、事前権限は不要とされる。 PA-Seriesではroot権限でのコード実行、VM-SeriesではDoS、Prisma AccessとCloud NGFWでは認証済みアクセスが必要な影響に限定される。 影響するのはPAN-OS 10.2、11.1、11.2、12.1、12.2の各修正版未満。修正版は12.2.3、12.1.4-h10/12.1.7-h5/12.1.10、11.2.13-h2、11.1.16-h2、10.2.18-h10など。 回避策はなく、Palo Alto Networksは更新を最優先としている。現時点で実悪用は確認されていない。 https://gbhackers.com/palo-alto-pan-os-buffer-overflow/

    Post summary

    Palo Alto Networks publicly disclosed CVE-2026-0310, a buffer overflow that allows root‑level code execution on PA‑Series devices, with no evidence of current exploitation and no workaround, urging urgent patching.

    0311033.6K
    15.0K followersView on X
  • hiro_@papa_anniekey

    Paloのこの脆弱性、エライコッチャとAIに書かせて騒いでいるの見かけたけど、データプレーンに影響が、が結構謎。 データとコントロール双方で使っているロジックとCPUが同じなのかな? https://security.paloaltonetworks.com/CVE-2026-0310

    200671.5K
    7.8K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    VPNにも使われるファイアウォールの脆弱性。 対応が遅れると、デジタル庁の二の舞に。 CVE-2026-0310 — PAN-OSのXML処理にバッファオーバーフロー。 PA-Series(物理機)では、未認証でroot権限の任意コード実行につながる。 しかも管理画面だけではない。 外部からファイアウォールの通信インターフェースに到達できれば攻撃対象になる。 攻撃に成功すれば、PA-Seriesではroot権限でコードを実行される。 「管理画面を外部に公開していないから大丈夫」 では済まない。 PA-Seriesはファイアウォールだが、GlobalProtectのVPNゲートウェイとしても使われる。 そもそも外部ネットワークとの境界に置かれる機器だ。 複数のPalo Alto製ファイアウォールを集中管理するPanoramaも対象。 ワークアラウンドはない。 対策はパッチ適用のみ。 Palo Alto Networks自身が、 Urgency: HIGHEST としている。 AIを使った脅威監視・防御を進めていても、 PAN-OS自身の脆弱性は、結局パッチを当てる必要がある。 デジタル庁も、既知のVPN機器の脆弱性への対応で優先順位を誤り、侵入を許した。 現時点で悪用は報告されていない。 今なら先に塞げる。 #PANOS #PaloAltoNetworks #GlobalProtect #CVE20260310 #脆弱性 #サイバーセキュリティ

    Post summary

    CVE‑2026‑0310 is a high‑urgency buffer overflow in PAN‑OS XML processing that can lead to unauthenticated root code execution on PA‑Series firewalls; no active exploitation has been reported and only a patch is available.

    110351.8K
    856 followersView on X
  • HOL@HashgraphOnline
    Patch

    Your PA-Series firewall can take a root shell from one unauthenticated XML packet to management web or the dataplane. No special config. Urgency HIGHEST from Palo Alto. Patch the fixed hotfix for your train. CVE-2026-0310 https://hol.org/blog/cve-2026-0310-pan-os-xml-buffer-overflow-unauth-root https://t.co/fX5TTLY8tx

    Post summary

    The text announces a high‑urgency vulnerability (CVE‑2026‑0310) affecting Palo Alto PA‑Series firewalls, urging users to apply the hotfix; a blog link likely contains PoC details but no exploit code or active exploitation is mentioned.

    111411.3K
    19.1K followersView on X
  • Previdian@PrevidianCyber
    General

    Ah shit, here we go again... CVE-2026-0310 https://t.co/cuBvW2KnWa

    Post summary

    The tweet merely references CVE-2026-0310 without providing any further details, making it a generic mention with no actionable information.

    02030429
    45 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #PaloAlto published an advisory addressing multiple security issues in #PAN-OS, including the buffer overflow vulnerability #CVE-2026-0310 CVSS:7.2. More information at: https://security.paloaltonetworks.com/CVE-2026-0310 #Patch #Patch #Patch

    Post summary

    Palo Alto Networks issued a patch advisory for CVE-2026‑0310, a buffer overflow flaw in PAN‑OS with CVSS 7.2, directing readers to a link for the patch and related details.

    01111455
    7.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately. #PANOS #BufferOverflow #CVE20260310 #Cybersecurity #PaloAltoNetworks https://securityonline.info/pan-os-buffer-overflow-flaw/ https://t.co/z4eyKhMpbT

    Post summary

    A new PAN-OS buffer overflow flaw (CVE-2026-0310) enables remote code execution, and users are urged to apply patches immediately; no exploit code or active exploitation evidence is mentioned.

    00022541
    13.0K followersView on X
  • Spy_Unkn0wn@Spy_Unkn0wn

    CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing. https://codeberg.org/Spy_Unkn0wn/PAN-OS I wrote this a fey days ago so... since it is not that useful to me, i will share it (still in test, may not work as expected).

    00012132
    958 followersView on X
  • Spy_Unkn0wn@Spy_Unkn0wn

    @PadhiyarRushi hey man, take a look on public poc about CVE-2026-0310, is on my profile x)

    0000078
    958 followersView on X
  • iototsecnews@iototsecnews

    Palo Alto PAN-OS の脆弱性 CVE-2026-0310 が FIX:バッファ・オーバーフローによる任意のコード実行 https://iototsecnews.jp/2026/09/10/palo-alto-pan-os-buffer-overflow-lets-attackers-execute-arbitrary-code-as-root/ Palo Alto Networks の PAN-OS に存在する XML 処理の不備に起因するバッファ・オーバーフローの脆弱性 CVE-2026-0310 が確認されました。PA-Series などのハードウェア・ファイアウォールが対象となります。この問題は、特別な条件を必要とせず遠隔から悪用される可能性があり、最高権限での任意のコード実行につながります。影響として、セキュリティ機能の無効化/設定の改ざん/内部ネットワークへの不正アクセスの発生が懸念されます。現場の担当者に求められるのは、修正済みリリースへの速やかなアップデートの適用/インターネットから到達可能な管理画面のアクセス遮断/信頼できる内部 IP アドレスからの接続制限の設定です。 #CVE20260310 #PaloAlto #PANOS #Vulnerability

    00000178
    513 followersView on X
  • Jim Nitterauer@JNitterauer

    Palo Alto PAN-OS buffer-overflow flaw (CVE-2026-0310) via XML processing — Palo Alto Networks disclosed CVE-2026-0310, a buffer-overflow vulnerability in PAN-OS triggered through XML processing,… #CyberSecurity #InfoSec https://security.paloaltonetworks.com/CVE-2026-0310

    00000175
    8.5K followersView on X
  • Modokey@modokey
    Disclosure

    “CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing” https://htn.to/44h5hyhM2p

    Post summary

    The post announces CVE-2026-0310, a PAN‑OS buffer overflow vulnerability involving XML processing, linking to additional details.

    00000154
    310 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Palo Alto Networks Cloud NGFW and other products (CVE-2026-0310) https://vuldb.com/vuln/401947/cti

    Post summary

    The post signals that CVE-2026-0310 is likely being exploited against Palo Alto Networks Cloud NGFW, but it provides no technical details or mitigation guidance.

    00000208
    2.3K followersView on X
  • しーにゃ♪@公式@Syynya
    Patch

    Palo Alto Networks、PAN-OSの脆弱性 CVE-2026-0310を修正 PA-Seriesで未認証root RCE、VM-SeriesはDoS https://rocket-boys.co.jp/security-measures-lab/palo-alto-pan-os-cve-2026-0310-update/

    Post summary

    The text announces that Palo Alto Networks has released a patch for CVE-2026-0310, addressing unauthenticated root RCE on PA‑Series and a DoS issue on VM‑Series.

    00000174
    915 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Palo Alto Networks、PAN-OSの脆弱性 CVE-2026-0310を修正 PA-Seriesで未認証root RCE、VM-SeriesはDoS https://rocket-boys.co.jp/security-measures-lab/palo-alto-pan-os-cve-2026-0310-update/ #セキュリティ対策Lab #security #securitynews #セキュリティ

    Post summary

    The article reports that Palo Alto Networks have released a patch for CVE-2026-0310, which impacted PA‑Series with unauthenticated root RCE and VM‑Series with DoS. The update confirms the vulnerability is addressed.

    00000263
    645 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Severe PAN-OS CVE-2026-0310 just revealed: a buffer overflow in XML processing lets attackers run arbitrary code as root on PA-Series firewalls. Affects physical appliances, cloud NGFW, VM-Series; no workaround available. Tighten network access, restrict management interfaces, update to PAN-OS 12.2.3+. #Security #Cybersecurity #PANOS #Vulnerability #Cybersecurity #PANOS #Vulnerability #RootAccess #FirewallSecurity #NetworkDefense https://thedailytechfeed.com/pan-os-buffer-overflow-lets-attackers-run-root-code-remotely/

    Post summary

    The post announces a new PAN‑OS CVE‑2026‑0310, details a buffer overflow that grants root access, and urges a patch upgrade to PAN‑OS 12.2.3+.

    00000189
    723 followersView on X
  • sunil kumawat@Sunil_kumawat17
    Patch

    @HashgraphOnline CVE-2026-0310 hits PAN-OS XML processing from the management or dataplane path: root RCE risk on PA-Series, DoS on VM-Series. Lock management to trusted IPs and bump to the fixed trains Palo Alto listed (e.g. 12.2.3 / 12.1.10 / 11.2.13-h2 class).

    Post summary

    The tweet announces a root RCE and DoS vulnerability in PAN‑OS XML processing, advises restricting management access and upgrading to the listed fixed firmware versions.

    00000170
    17 followersView on X
  • ぽつぽち@poppo9494
    General

    dataplane interfaceにアクセスできるだけでいいなら影響大きい気が。。 >unauthenticated attacker with network access to the management web or dataplane interface https://security.paloaltonetworks.com/CVE-2026-0310

    Post summary

    The post references CVE-2026-0310 and notes that unauthenticated network access to management or dataplane interfaces is possible, but it does not provide PoC, exploit code, patch information, or evidence of active exploitation.

    00000214
    38 followersView on X

Explore more