Column 1
Skip to content

PAN-OS CVE-2026-0310: Check Firewall Type and Patch Branch

September 10, 2026

PAN-OS CVE-2026-0310 requires a firewall-type and software-branch check before maintenance. Palo Alto Networks describes possible root-level code execution on PA-Series hardware and denial of service on VM-Series firewalls. Panorama is also affected. The vendor reports no known malicious exploitation. This is not a CISA KEV announcement.

Scope note: Fix I.T. Phill has not assessed your firewall or confirmed exposure or compromise. The generic network-security illustration is not a screenshot of PAN-OS, an affected appliance, or a completed repair.

Match the advisory to the system you operate

The official advisory, published and updated September 9, 2026, distinguishes PA-Series, VM-Series, Panorama, Prisma Access and Cloud NGFW. Its highest listed threat-adjusted score is 7.2; the hardware case has a 9.2 base score. These scores do not describe every deployment equally.

Record the product, installed release and maintenance branch using your normal administration interface. Keep a separate inventory entry for each member of a high-availability pair and for its management system. Do not substitute an application agent’s version for the firewall version.

Choose a supported update path

The vendor lists fixed releases across several branches, including PAN-OS 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 and 10.2.18-h10. These are examples from the current solution table, not a universal upgrade sequence. The table also provides lower maintenance hotfix alternatives. Match your starting release to its exact row and check the supported upgrade path before selecting an image.

For Prisma Access and Cloud NGFW, the vendor describes scheduled service maintenance and an option to request an earlier upgrade through support. Do not treat a self-managed appliance image as an instruction to update a managed service yourself.

  1. Confirm the system owner, service dependencies, support entitlement and maintenance contact.
  2. Read the current vendor solution table and release notes for the selected destination. Check platform support and required intermediate releases.
  3. Prepare a recoverable configuration copy through your established customer-approved process. Document recovery access and rollback limitations before starting. This article does not change any backup schedule.
  4. For high-availability deployments, agree the supported member order, health checks and failover plan. Allow time to investigate unexpected health changes before continuing.
  5. Notify the people who depend on remote access or protected applications, then use the vendor-supported update workflow.

Protect access while arranging maintenance

Palo Alto Networks recommends limiting management access to trusted internal systems. The advisory states that there is no known workaround. Access restrictions are risk reduction, not evidence that a vulnerable build has been repaired. Have the responsible administrator assess any access-policy change separately; do not make an unplanned remote-access change that could lock the team out.

Verify the result without testing the vulnerability

  • Confirm the installed release after maintenance and match it to the current vendor table. Record the check time and exact branch.
  • Check management connectivity, high-availability health, routing and the normal applications or VPN workflows relevant to your deployment.
  • Review ordinary administrative and security monitoring for unexpected changes, service failures or unexplained privileged activity. Escalate concerns through your incident-response process.
  • Keep the maintenance result separate from a compromise assessment. Installing an update alone does not establish that an earlier compromise is absent.

Keep the maintenance record specific

Record what was updated, what was verified and what still needs investigation. For hosted WordPress or ecommerce services behind the appliance, include the application owner in the service check. Our WordPress support team can help coordinate application-level verification without claiming to have assessed the firewall.

The older July PAN-OS advisory checklist and CVE-2026-0257 GlobalProtect guide cover different advisories. Do not use their version boundaries for CVE-2026-0310.

Sources and timing

Reviewed September 10, 2026: Palo Alto Networks advisory and solution table and the vendor CNA record. The vendor page dates publication to September 9; the September 10 CNA and NVD arrivals are separate timestamps, not proof of a newly started attack campaign. Consult the current advisory again at maintenance time.