Palo Alto Networks security advisory (AV26-905)
Serial number: AV26-905 Date: September 10, 2026 As of September 10, 2026, Palo Alto Networks is affected by vulnerabilities in the following products: Cloud NGFW All on AWS*, All on Azure* PAN-OS Multiple versions Prisma Access Multiple versions Prisma Browser Prior to 151.26.5.170 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) Palo Alto Networks Security Advisories
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-905
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-0310 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellencert-bund
- unknownCVE-2026-0310: A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-O…nvd
- unknownPalo Alto Products Multiple Vulnerabilitieshkcert
- highCVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)paloalto
Recent advisories for Palo Alto Networks
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Progra…cert-bund · 2026-09-10
- low[NEU] [niedrig] Palo Alto Networks Checkov by Prisma Cloud: Mehrere Schwachstellen ermöglichen Codeausführungcert-bund · 2026-09-10
- high[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellencert-bund · 2026-09-10
- high[NEU] [hoch] Palo Alto Networks GlobalProtect App: Schwachstelle ermöglicht Privilegieneskalationcert-bund · 2026-09-10
- unknownCVE-2026-0304: A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an auth…nvd · 2026-09-10
- unknownCVE-2026-0303: A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitra…nvd · 2026-09-10
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…2026-09-09
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalCisco security advisory (AV26-197) – Update 32026-09-09
- criticalFortinet security advisory (AV26-023) - Update 12026-09-09