<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PAN-OS (10.2 &lt; 10.2.18-H10) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pan-os-10.2--10.2.18-h10/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 18:58:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pan-os-10.2--10.2.18-h10/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-0308 Stored XSS in PAN-OS Web Interface</title><link>https://feed.craftedsignal.io/briefs/2026-09-panos-xss/</link><pubDate>Wed, 09 Sep 2026 18:58:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-panos-xss/</guid><description>A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows an authenticated administrator to execute arbitrary JavaScript within the context of the management interface.</description><content:encoded><![CDATA[<p>CVE-2026-0308 is a stored cross-site scripting (XSS) vulnerability affecting Palo Alto Networks PAN-OS software. The vulnerability resides in the web-based management interface, enabling a malicious authenticated administrator to inject and store arbitrary JavaScript payloads. When other users access the affected web interface, the stored payload executes in their browser context. The vulnerability is applicable to PA-Series and VM-Series firewalls, as well as Panorama management appliances. Although the vulnerability requires high privileges (authenticated administrator access), it is accessible over the network. Palo Alto Networks has confirmed that no malicious exploitation has been observed in the wild. Customers are advised to upgrade to the specified patched versions to remediate the vulnerability, as no workarounds are currently available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability could allow an authenticated attacker to compromise the sessions of other administrators accessing the PAN-OS management interface. This may lead to unauthorized actions performed on behalf of legitimate administrators, potentially impacting the integrity of the firewall configuration or management operations. The severity is assessed as low by the vendor, and the vulnerability does not impact Cloud NGFW or Prisma Access.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all affected PA-Series, VM-Series, and Panorama appliances to the recommended fixed versions immediately:</li>
</ol>
<ul>
<li>For PAN-OS 12.1, upgrade to version 12.1.10 or later.</li>
<li>For PAN-OS 11.2, upgrade to version 11.2.13-h2 or later.</li>
<li>For PAN-OS 11.1, upgrade to version 11.1.16-h2 or later.</li>
</ul>
<ol start="2">
<li>Implement network segmentation by restricting management interface access to a dedicated jump box or trusted management subnet to limit exposure.</li>
<li>If Threat Prevention is licensed, enable Threat ID 510040 and 510041 and ensure appropriate SSL decryption is configured for inbound management traffic to facilitate inspection.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>xss</category><category>web-vulnerability</category><category>pan-os</category><category>cve</category><category>rce</category><category>network-security</category><category>vulnerability</category><category>panos</category></item></channel></rss>