Palo Alto Networks Discovers Multiple Vulnerabilities in PAN-OS and GlobalProtect

Palo Alto Networks Discovers Multiple Vulnerabilities in PAN-OS and GlobalProtect

First seen 10 Sep 2026, 04:45 UTC Hkcertsecurity.paloaltonetworks.comcve.mitre.org 64.5

Article Content

Browse articles
ThreatCluster

Palo Alto Networks has disclosed several vulnerabilities affecting its PAN-OS and GlobalProtect products, including CVE-2026-0310, a buffer overflow allowing denial of service and arbitrary code execution on PA-Series firewalls. Other vulnerabilities include CVE-2026-0309, a command injection flaw for authenticated users with Luna HSM, and CVE-2026-0307, which allows local privilege escalation in the GlobalProtect app. CVE-2026-0308 introduces a stored XSS vulnerability in the web interface. The vulnerabilities affect various versions of PAN-OS and GlobalProtect across multiple platforms. Palo Alto Networks is not aware of any active exploitation of these vulnerabilities. Urgent patches are recommended for affected systems, with specific upgrade paths provided for various versions. The overall risk is heightened for PA-Series firewalls due to the potential for arbitrary code execution.

Key Points: • Multiple vulnerabilities disclosed in Palo Alto Networks products, including CVE-2026-0310 and CVE-2026-0309. • CVE-2026-0310 poses a high risk of remote code execution on PA-Series firewalls. • Palo Alto Networks recommends immediate upgrades to mitigate risks associated with these vulnerabilities.

Ask AI about this cluster

Timeline

2026-09-10
CVE-2026-0310 published
A buffer overflow vulnerability in PAN-OS allows denial of service and arbitrary code execution on PA-Series firewalls.
security.paloaltonetworks.com
2026-09-10
CVE-2026-0309 published
An authenticated command injection vulnerability in PAN-OS allows root command execution for users with Luna HSM.
security.paloaltonetworks.com
2026-09-10
CVE-2026-0307 published
Local privilege escalation vulnerabilities in GlobalProtect allow users to execute commands with elevated privileges.
security.paloaltonetworks.com
2026-09-10
CVE-2026-0308 published
A stored XSS vulnerability in PAN-OS allows authenticated users to execute JavaScript payloads.
security.paloaltonetworks.com
2026-09-10
HKCERT bulletin released
HKCERT reports multiple vulnerabilities in Palo Alto products, including remote code execution and privilege escalation risks.
Hkcert