Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-0286

CVE-2026-0286: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityHigh8.5

    High [CVE-2026-0286] PAN-OS: Authenticated Command Injection in CLI

    CVE-2026-0286Source published

    A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

    Affected products in this advisory
    • PAN-OS
    Source-reported affected versions
    • PAN-OS < 12.1.8
    • PAN-OS < 11.2.13
    • PAN-OS < 11.1.16
    • PAN-OS < 10.2.18-h8
    Source-reported fixed versions
    • PAN-OS >= 12.1.8
    • PAN-OS >= 12.1.7-h2
    • PAN-OS >= 12.1.4-h8
    • PAN-OS >= 11.2.13

    14 more entries in the full advisory.

    Mitigation guidance
    • VersionMinor VersionSuggested SolutionCloud NGFW AllNo action needed.
    • PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later.
    Workarounds
    • Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510036 (from Applications and Threats content version 9122-10145 and later).
    • For these Threat IDs to protect against attacks for this vulnerability:
    • Route incoming traffic for the MGT port through a DP port, e.g., enabling management profile on a DP interface for management access.Replace the Certificate for Inbound Traffic Management.
    • Decrypt inbound traffic to the management interface so the firewall can inspect it.Enable threat prevention on the inbound traffic to management services.

    1 more entries in the full advisory.

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery