Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3477 articles · 182402 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-0286EXPLOITEDPATCHED
palo alto networks · cloud ngfw

PAN-OS: Authenticated Command Injection in CLI

Description

A vulnerability labeled as very critical has been found in Palo Alto PAN-OS and Panorama. This issue affects some unknown processing of the component Management Plane. Such manipulation leads to os command injection. This vulnerability is uniquely identified as CVE-2026-0286. The attack can be launched remotely.

Affected Products

VendorProductVersions
palo alto networkscloud ngfw12.1.0, 11.2.0, 11.1.0, 10.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
palo alto networkspan-osmitre_affected90%
palo alto networksprisma accessmitre_affected90%

References

  • https://security.paloaltonetworks.com/CVE-2026-0286(vendor-advisory)

Related News (1 articles)

Tier C
VulDB20d ago
CVE-2026-0286 | Palo Alto PAN-OS/Panorama Management Plane os command injection
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
All12.1.811.2.1311.1.1610.2.18-h8
CWECWE-78
PublishedJul 9, 2026
Last enriched20d agov2
Trending Score2
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-0300EXP
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Trending: 110
NONECVE-2026-0257EXP
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Trending: 41
NONECVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Trending: 18
NONECVE-2026-0288
PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Trending: 17
CRITICALCVE-2026-0284EXP
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 9, 2026
Discovered by ZDM
Jul 9, 2026
Actively Exploited
Jul 9, 2026
Patch Available
Jul 9, 2026
Updated: description, severity, activelyExploited
Jul 9, 2026

Version History

v2
Last enriched 20d ago
v2Tier C20d ago

Updated description with new details, changed product to 'panorama', updated severity to HIGH, and marked as actively exploited.

descriptionseverityactivelyExploited
via VulDB
v120d ago

Initial creation