CVE-2026-0309: Palo Alto Networks Cloud Ngfw
Medium severity, CVSS 4.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM). The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Affected products
- Palo Alto Networks Cloud Ngfw
- Palo Alto Networks PAN-OS: from 12.2.0, before 12.2.3 (fixed in 12.2.3); from 12.1.0, before 12.1.4-h10 (fixed in 12.1.4-h10); from 11.2.0, before 11.2.4-h21 (fixed in 11.2.4-h21); from 11.1.0, before 11.1.4-h36 (fixed in 11.1.4-h36); from 10.2.0, before 10.2.7-h37 (fixed in 10.2.7-h37)
- Palo Alto Networks Prisma Access
Published 2026-09-10. Last modified 2026-09-11.