Multiple security vulnerabilities have been identified in Palo Alto Networks PAN-OS, affecting the web management interface and the Command Line Interface (CLI). These flaws include a stored cross-site scripting (XSS) vulnerability and a privilege escalation vulnerability that could allow authenticated administrators to execute unauthorized actions or gain root-level privileges on affected devices. The vulnerabilities impact PA-Series, VM-Series firewalls, and Panorama appliances, while Cloud NGFW and Prisma Access are not affected. Although Palo Alto Networks is not aware of active exploitation of these issues, organizations should promptly apply the available security updates to reduce the risk of administrative compromise.
• CVE-2026-0266 – A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows a malicious authenticated administrator to store a JavaScript payload that executes when another administrator accesses the affected page. Successful exploitation could enable unauthorized actions by abusing the victim administrator's authenticated session.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Palo Alto Networks PAN-OS, affecting the web management interface and the Command Line Interface (CLI). These flaws include a stored cross-site scripting (XSS) vulnerability and a privilege escalation vulnerability that could allow authenticated administrators to execute unauthorized actions or gain root-level privileges on affected devices. The vulnerabilities impact PA-Series, VM-Series firewalls, and Panorama appliances, while Cloud NGFW and Prisma Access are not affected. Although Palo Alto Networks is not aware of active exploitation of these issues, organizations should promptly apply the available security updates to reduce the risk of administrative compromise.
• CVE-2026-0266 – A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows a malicious authenticated administrator to store a JavaScript payload that executes when another administrator accesses the affected page. Successful exploitation could enable unauthorized actions by abusing the victim administrator's authenticated session.[emaillocker id="1283"]
• CVE-2026-0272 – A privilege escalation vulnerability in the PAN-OS Command Line Interface (CLI) allows an authenticated administrator with CLI access to perform actions with root privileges on the affected device. The risk is significantly reduced by restricting CLI access to trusted administrators and limiting management interface access to trusted internal IP addresses.
These vulnerabilities present a moderate risk to organizations managing Palo Alto Networks firewalls and Panorama appliances. Successful exploitation could result in unauthorized administrative actions, privilege escalation, and compromise of firewall management infrastructure. Organizations should upgrade to the latest fixed PAN-OS releases, restrict management and CLI access to trusted administrators, and follow Palo Alto Networks' recommended management interface hardening practices to minimize the risk of exploitation.
We recommend you to upgrade PAN-OS to version 12.1.5 or later.
The following reports contain further technical details:
[/emaillocker]