A vulnerability labeled as very critical has been found in Palo Alto PAN-OS and Panorama. This issue affects some unknown processing of the component Management Plane. Such manipulation leads to os command injection. This vulnerability is uniquely identified as CVE-2026-0286. The attack can be launched remotely.
| Vendor | Product | Versions |
|---|---|---|
| palo alto networks | cloud ngfw | 12.1.0, 11.2.0, 11.1.0, 10.2.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| palo alto networks | pan-os | mitre_affected | 90% |
| palo alto networks | prisma access | mitre_affected | 90% |
Updated description with new details, changed product to 'panorama', updated severity to HIGH, and marked as actively exploited.
Initial creation