security.paloaltonetworks.com
Palo Alto Networks Discovers Multiple Vulnerabilities in PAN-OS and GlobalProtect
Article Content
Palo Alto Networks has disclosed several vulnerabilities affecting its PAN-OS and GlobalProtect products, including CVE-2026-0310, a buffer overflow allowing denial of service and arbitrary code execution on PA-Series firewalls. Other vulnerabilities include CVE-2026-0309, a command injection flaw for authenticated users with Luna HSM, and CVE-2026-0307, which allows local privilege escalation in the GlobalProtect app. CVE-2026-0308 introduces a stored XSS vulnerability in the web interface. The vulnerabilities affect various versions of PAN-OS and GlobalProtect across multiple platforms. Palo Alto Networks is not aware of any active exploitation of these vulnerabilities. Urgent patches are recommended for affected systems, with specific upgrade paths provided for various versions. The overall risk is heightened for PA-Series firewalls due to the potential for arbitrary code execution.
Key Points: • Multiple vulnerabilities disclosed in Palo Alto Networks products, including CVE-2026-0310 and CVE-2026-0309. • CVE-2026-0310 poses a high risk of remote code execution on PA-Series firewalls. • Palo Alto Networks recommends immediate upgrades to mitigate risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.