CVE-2026-0284
published 2026-07-09CVE-2026-0284: An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with…
PriorityP260critical9.9CVSS 3.1
AVNACLPRNUINSCCHILAL
EPSS
0.46%
38.8th percentile
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Affected
210 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | pan-os | >= 10.2.0 < 10.2.7-h36 | 10.2.7-h36 |
| palo_alto_networks | pan-os | >= 11.1.0 < 11.1.4-h35 | 11.1.4-h35 |
| palo_alto_networks | pan-os | >= 11.2.0 < 11.2.4-h20 | 11.2.4-h20 |
| palo_alto_networks | pan-os | >= 12.1.0 < 12.1.4-h8 | 12.1.4-h8 |
| paloalto | cloud_ngfw | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Enable Threat ID 510031 via Threat Prevention subscription (requires Applications and Threats content version 9122-10145 or later) and apply a vulnerability protection security profile to the GlobalProtect interface to detect/block exploitation attempts against the LSVPN XML injection vulnerability. ↗
- →The attack surface is the Large Scale VPN (LSVPN) functionality; monitor for unauthenticated network requests to LSVPN satellite endpoints containing injected or malformed XML content, which may indicate exploitation attempts targeting information disclosure or corruption of internal LSVPN satellite data. ↗
- ·Panorama, Cloud NGFW, and Prisma Access are explicitly NOT affected by this vulnerability; detection and patching efforts should focus solely on PAN-OS deployments with LSVPN enabled. ↗
- ·Threat ID 510031 provides only LIMITED coverage; it is not a full workaround. No known workarounds exist, and patching to a fixed PAN-OS version remains the recommended remediation. ↗
- ·The Threat ID protection requires the Applications and Threats content version 9122-10145 or later to be installed; earlier content versions will not include the signature. ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
nvdv4.04.7MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
vendor_paloalto·CVSS 7.8
CVE-2026-0284 CWE-74 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Affected products: Cloud NGFW, PAN-OS, Prisma Access
Solution: VERSION MINOR VERSION RANGE SUGGESTED SOLUTION
Cloud NGFW No action needed.
PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later.
12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later.
PAN-OS 11.2 11.2.11 through 11.2.12 Upgrade to 11.2.13 or later.
11.2.8
GHSA
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML conte
ghsa_unreviewed·2026-07-09
CVE-2026-0284 [MEDIUM] CWE-74 An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML conte
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
VulDB
Palo Alto Cloud NGFW/PAN-OS/Prisma Access LSVPN xml injection (EUVD-2026-42677)
vuldb·2026-07-09·CVSS 4.7
CVE-2026-0284 [MEDIUM] Palo Alto Cloud NGFW/PAN-OS/Prisma Access LSVPN xml injection (EUVD-2026-42677)
A vulnerability classified as critical has been found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. The impacted element is an unknown function of the component LSVPN. The manipulation leads to xml injection.
This vulnerability is referenced as CVE-2026-0284. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-09
Published