Palo Alto Networks has patched a command injection vulnerability in PAN-OS that could allow authenticated administrators to execute arbitrary operating system commands with root privileges, prompting organizations to prioritize upgrades across affected firewall deployments.
The most significant flaw, tracked as CVE-2026-0273, affects PA-Series and VM-Series firewalls as well as Panorama management appliances running multiple PAN-OS versions.
Rated 6.1 under the CVSS v4.0 scoring system, the vulnerability stems from improper input validation in the command-line interface (CLI) and web management interface. An authenticated administrator could exploit the flaw to bypass normal system restrictions and execute arbitrary commands as the root user.
Because the vulnerability requires only valid administrative credentials and no special configuration, organizations exposing management interfaces to semi-trusted networks face elevated post-compromise risk.
Palo Alto also disclosed two additional medium-severity vulnerabilities in the same advisory.
CVE-2026-0272 allows authenticated administrators to escalate privileges to root through the PAN-OS CLI, while CVE-2026-0269 is a memory corruption flaw that enables authenticated users to repeatedly reboot firewalls by sending specially crafted tunnel traffic.
The denial-of-service vulnerability affects deployments configured with IPsec tunnels or GlobalProtect gateways and can repeatedly force firewalls into maintenance mode, disrupting VPN connectivity and remote access services.
The company said Cloud NGFW and Prisma Access are not affected by any of the three vulnerabilities.
Importantly, Palo Alto stated that it is not aware of any malicious exploitation of the vulnerabilities at the time of disclosure.
Security teams are nevertheless being urged to patch quickly because the flaws provide significant leverage once an attacker gains administrative access.
Palo Alto recommends upgrading to the latest supported releases rather than relying on configuration changes alone, particularly for organizations still running older PAN-OS branches.
The company also advises restricting firewall management interfaces to trusted internal IP addresses, limiting CLI access to a small group of administrators and using hardened jump servers as the only systems permitted to access management interfaces.
Organizations with a Threat Prevention subscription can additionally enable dedicated Threat IDs that detect and block exploitation attempts for CVE-2026-0273, provided management traffic traverses a data-plane interface and is decrypted for inspection.
Unlike the command injection and privilege escalation flaws, Palo Alto said there is no practical workaround for the tunnel denial-of-service vulnerability beyond upgrading affected systems.
For enterprise security teams, the advisory highlights the continued importance of securing management interfaces. Although all three vulnerabilities require authenticated access, successful exploitation could enable attackers to obtain root control over security appliances or disrupt VPN infrastructure, making timely patching and strict administrative access controls a high priority.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




