Skip to content

Palo Alto Networks Patches PAN-OS Command Injection CVE-2026-0273 Across All Active Branches

Palo Alto Networks has patched CVE-2026-0273, a command injection vulnerability in the PAN-OS web management interface that allows authenticated administrators to execute arbitrary OS commands on the firewall. The vulnerability affects PAN-OS versions 10.1 through 11.2 and all active GlobalProtect gateway configurations. Updates are available across all supported branches.

Article network-security

Palo Alto Networks has released PAN-OS updates across all supported software branches patching CVE-2026-0273, a command injection vulnerability in the PAN-OS web management interface (Web UI). The vulnerability allows an authenticated administrator with access to the web management interface to inject OS commands that execute with root privilege on the underlying firewall operating system.

Vulnerability Details

CVE-2026-0273 (CVSS assessed as High): Authenticated OS command injection in PAN-OS Web UI. The vulnerability exists in a diagnostic or configuration page where user-supplied input is processed without adequate sanitisation before incorporation into a system command.

Authentication requirement: Requires existing administrative access to the PAN-OS management interface. This means the direct exploitation path is limited to:

  • Threat actors who have compromised administrator credentials for the firewall management interface
  • Insider threats or contractors with delegated administrative access
  • Attackers who have exploited a prior vulnerability to gain management interface access

Affected versions: PAN-OS 10.1, 10.2, 11.0, 11.1, and 11.2 on all hardware and VM-Series firewalls. Panorama management instances are also affected.

Fixed versions: PAN-OS 10.1.12-h9, 10.2.13-h1, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1 and later.

Scope and Risk Assessment

While CVE-2026-0273 requires authentication, authenticated administrative access to a PAN-OS firewall carries significant consequence if elevated through command injection:

Configuration exfiltration: Administrative shell access allows extracting the complete PAN-OS running configuration, including VPN pre-shared keys, local user credentials, RADIUS/LDAP integration credentials, and certificate private keys.

Certificate extraction: SSL/TLS inspection certificates, GlobalProtect gateway certificates, and management interface certificates stored on the firewall are accessible from the root shell.

Traffic interception: With root access to an active firewall, an attacker can reconfigure traffic forwarding rules, insert traffic mirroring, or disable security policies without the changes being visible through the standard administrative interface.

Persistence: Root-level access allows modification of PAN-OS system files for persistence β€” changes that survive configuration restore from the web UI.

GlobalProtect Implications

CVE-2026-0273 affects GlobalProtect gateway configurations. GlobalProtect gateways handle VPN authentication and are often the most exposed PAN-OS management surface. If management interface access is available from GlobalProtect-adjacent networks (a misconfiguration), the blast radius extends to any system the GlobalProtect VPN can reach.

Palo Alto Networks’ best practice guidance β€” isolating management interfaces on a dedicated out-of-band management network β€” limits the exploitability of CVE-2026-0273 by restricting which IP addresses can reach the management interface. Organisations that have not isolated PAN-OS management to a dedicated network should treat this vulnerability as a prompt to implement that segmentation.

Update PAN-OS: Apply the fixed version for your software branch from the Palo Alto Networks Customer Support Portal. If running an older minor version (10.1.x before 10.1.12-h9), the update path may require a feature release upgrade before applying the security patch.

Verify management interface access control: Confirm that the PAN-OS management interface (HTTPS port 443) is accessible only from the designated management IP range. Use Security > Access Control > Management Interface Access in the PAN-OS web UI or equivalent Panorama policy to restrict source addresses.

Audit administrative accounts: Review active administrator accounts in PAN-OS and verify that no unexpected accounts have been created. Review recent admin session logs (Device > Log > System, filtered by β€œadmin”) for authentication from unusual IP addresses.

Panorama: If Panorama is used for centralised management, apply the PAN-OS updates to Panorama first β€” Panorama manages firewall configurations and a compromised Panorama instance has administrative reach across all managed firewalls.

Share this article

Related Intelligence

🌐 Network

PAN-OS CVE-2026-0300 β€” Unauthenticated RCE Zero-Day Actively Exploited in Firewall Espionage Attacks

A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS has been under active exploitation since at least early April 2026, linked to espionage-motivated threat actors targeting government and critical infrastructure networks. CVE-2026-0300 affects the User-ID authentication portal on VM-Series and hardware firewalls; CISA added it to the KEV catalogue on 6 May 2026. Patches are available β€” apply immediately.

#palo-alto +9
🌐 Network

Palo Alto PAN-OS CVE-2026-3197: SAML Auth Bypass Under Mass Exploitation by Nation-State Actors

A critical SAML authentication bypass in Palo Alto Networks PAN-OS GlobalProtect allows unauthenticated remote attackers to gain administrative firewall access. CVE-2026-3197 chains with a command injection flaw to achieve root-level OS execution and is being exploited by at least three distinct threat actor clusters including a China-nexus nation-state group. CISA has added it to the KEV catalogue.

#palo-alto +10
🌐 Network

PAN-OS GlobalProtect Denial-of-Service CVE-2026-0227 β€” PoC Published, Firewalls Risk Forced Maintenance Mode

A proof-of-concept exploit has been published for CVE-2026-0227, a denial-of-service vulnerability in Palo Alto Networks PAN-OS affecting GlobalProtect gateways and portals. An unauthenticated remote attacker can crash the firewall into a mandatory maintenance mode by sending malformed requests to the GlobalProtect interface. Prisma Access deployments are also affected. Palo Alto has released patches; the PoC significantly elevates exploitation risk.

#palo-alto +7