Wire Observer.
Technology

Critical PAN-OS Flaw Lets Remote Attackers Hijack Palo Alto Firewalls

Critical PAN-OS Flaw Lets Remote Attackers Hijack Palo Alto Firewalls

Palo Alto Networks has warned customers of a high‑severity vulnerability in its PAN‑OS operating system that could let an unauthenticated attacker take full control of PA‑Series hardware firewalls.

The flaw, catalogued as CVE‑2026‑0310, resides in the way PAN‑OS parses XML data. By sending a specially crafted XML payload to a vulnerable device, an attacker can trigger arbitrary code execution with root‑level privileges, effectively bypassing all authentication checks.

Root access on a firewall gives an adversary the ability to modify security policies, intercept or block traffic, and exfiltrate data traversing the network. Because PA‑Series appliances are widely deployed in enterprises, data centers, and service‑provider environments, the potential impact spans a broad range of critical infrastructure.

Palo Alto responded by publishing a security advisory and releasing firmware updates that address the XML‑processing weakness. The company urges all owners of affected models to apply the patches immediately and, where possible, to disable any non‑essential services that could be leveraged as an attack vector.

The discovery follows a pattern of high‑profile vulnerabilities in network‑security appliances that have attracted attention from both attackers and defenders. Experts note that firewalls, which sit at the junction of internal and external traffic, are especially attractive targets when a flaw permits remote code execution without credentials.

Several national computer‑security incident response teams have issued notices echoing Palo Alto’s recommendations, emphasizing the urgency of remediation before the vulnerability can be weaponized in the wild. No public exploits have been reported to date, but the open‑source security community has already begun analyzing the advisory for proof‑of‑concept code.

Organizations are advised to verify the firmware version on each PA‑Series device, deploy the vendor’s patches, and monitor system logs for unusual XML‑related activity. In addition, revisiting network segmentation and employing defense‑in‑depth measures can mitigate the damage should an attacker manage to bypass the initial safeguard.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related