CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)
Details
Original advisory: https://security.paloaltonetworks.com/CVE-2026-0308
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-0308 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for PAN-OS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellencert-bund · 2026-09-10
- unknownCVE-2026-0310: A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-O…nvd · 2026-09-10
- unknownCVE-2026-0309: A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticat…nvd · 2026-09-10
- unknownCVE-2026-0308: A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enable…nvd · 2026-09-10
- mediumCVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration (Severity: MEDIUM)paloalto · 2026-09-09
- highCVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)paloalto · 2026-09-09
More from Palo Alto Networks Security Advisories
- mediumCVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows (Severity: MEDIUM)2026-09-09
- lowCVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File (Severity: LOW)2026-09-09
- highPAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) (Severity: HIGH)2026-09-09
- lowCVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability (Severity: LOW)2026-09-09
- highCVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)2026-09-09