NCSC-2026-0369 [1.00] [M/H] Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS
Palo Alto Networks heeft een kwetsbaarheid verholpen in PAN-OS software, specifiek voor VM-Series en PA-Series firewalls, evenals Panorama management software. De kwetsbaarheid betreft een buffer overflow in de XML-verwerkingsfunctionaliteit van PAN-OS. Ongeauthenticeerde aanvallers met netwerktoegang kunnen hierdoor een denial-of-service veroorzaken op VM-Series firewalls of willekeurige code uitvoeren met rootrechten op PA-Series firewalls. Ook Panorama management software is getroffen. De kwetsbaarheid ontstaat door onjuiste verwerking van XML-invoer, wat leidt tot geheugenbeschadiging en mogelijk volledige systeemcompromittering.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0369
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-03100.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-0310 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellencert-bund
- unknownPalo Alto Networks security advisory (AV26-905)cccs
- unknownCVE-2026-0310: A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-O…nvd
- unknownPalo Alto Products Multiple Vulnerabilitieshkcert
- unknownMultiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)cert-fr-avis
- highCVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)paloalto
Recent advisories for Kwetsbaarheid verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedNCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gatewayncsc-nl · 2026-09-14
- unknownexploitedNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editionsncsc-nl · 2026-09-12
- unknownexploitedNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Centerncsc-nl · 2026-09-11
- unknownexploitedNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-ablencsc-nl · 2026-09-11
- unknownexploitedNCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOSncsc-nl · 2026-09-10
- unknownNCSC-2026-0359 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Endpoint Manager Mobilencsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Samba2026-09-15
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS2026-09-15
- unknownNCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway2026-09-14
- unknownNCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azure2026-09-14
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12