cbcvebase.
CVE-2026-0284
published 2026-07-09

CVE-2026-0284: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with…

PriorityP260critical9.9CVSS 3.1
AVNACLPRNUINSCCHILAL
EPSS
0.46%
38.8th percentile
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Affected

210 ranges· showing 25
VendorProductVersion rangeFixed in
palo_alto_networkspan-os>= 10.2.0 < 10.2.7-h3610.2.7-h36
palo_alto_networkspan-os>= 11.1.0 < 11.1.4-h3511.1.4-h35
palo_alto_networkspan-os>= 11.2.0 < 11.2.4-h2011.2.4-h20
palo_alto_networkspan-os>= 12.1.0 < 12.1.4-h812.1.4-h8
paloaltocloud_ngfw
paloaltopan-os
paloaltoprisma_access
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os

Detection & IOCsextracted from sources · hover to see the quote

otherThreat ID 510031
  • Enable Threat ID 510031 via Threat Prevention subscription (requires Applications and Threats content version 9122-10145 or later) and apply a vulnerability protection security profile to the GlobalProtect interface to detect/block exploitation attempts against the LSVPN XML injection vulnerability.
  • The attack surface is the Large Scale VPN (LSVPN) functionality; monitor for unauthenticated network requests to LSVPN satellite endpoints containing injected or malformed XML content, which may indicate exploitation attempts targeting information disclosure or corruption of internal LSVPN satellite data.
  • ·Panorama, Cloud NGFW, and Prisma Access are explicitly NOT affected by this vulnerability; detection and patching efforts should focus solely on PAN-OS deployments with LSVPN enabled.
  • ·Threat ID 510031 provides only LIMITED coverage; it is not a full workaround. No known workarounds exist, and patching to a fixed PAN-OS version remains the recommended remediation.
  • ·The Threat ID protection requires the Applications and Threats content version 9122-10145 or later to be installed; earlier content versions will not include the signature.

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
nvdv4.04.7MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.