{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pan-os-11.1.0---11.1.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:palo_alto_networks:pan-os:12.1.2:*:*:*:*:*:*:*","cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:*:*:*:*:*:*","cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PAN-OS (12.1.2 - 12.1.9)","PAN-OS (11.2.0 - 11.2.13)","PAN-OS (11.1.0 - 11.1.16)","PAN-OS (12.2 \u003c 12.2.3)","PAN-OS (12.1 \u003c 12.1.10)","PAN-OS (11.2 \u003c 11.2.13-h2)","PAN-OS (11.1 \u003c 11.1.16-h2)","PAN-OS (10.2 \u003c 10.2.18-h10)","Panorama","VM-Series","PA-Series","Prisma Access","Cloud NGFW"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","pan-os","cve","rce","network-security","vulnerability","panos"],"_cs_type":"threat","_cs_vendors":["Palo Alto Networks"],"content_html":"\u003cp\u003eCVE-2026-0308 is a stored cross-site scripting (XSS) vulnerability affecting Palo Alto Networks PAN-OS software. The vulnerability resides in the web-based management interface, enabling a malicious authenticated administrator to inject and store arbitrary JavaScript payloads. When other users access the affected web interface, the stored payload executes in their browser context. The vulnerability is applicable to PA-Series and VM-Series firewalls, as well as Panorama management appliances. Although the vulnerability requires high privileges (authenticated administrator access), it is accessible over the network. Palo Alto Networks has confirmed that no malicious exploitation has been observed in the wild. Customers are advised to upgrade to the specified patched versions to remediate the vulnerability, as no workarounds are currently available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could allow an authenticated attacker to compromise the sessions of other administrators accessing the PAN-OS management interface. This may lead to unauthorized actions performed on behalf of legitimate administrators, potentially impacting the integrity of the firewall configuration or management operations. The severity is assessed as low by the vendor, and the vulnerability does not impact Cloud NGFW or Prisma Access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all affected PA-Series, VM-Series, and Panorama appliances to the recommended fixed versions immediately:\u003c/li\u003e\n\u003c/ol\u003e\n\u003cul\u003e\n\u003cli\u003eFor PAN-OS 12.1, upgrade to version 12.1.10 or later.\u003c/li\u003e\n\u003cli\u003eFor PAN-OS 11.2, upgrade to version 11.2.13-h2 or later.\u003c/li\u003e\n\u003cli\u003eFor PAN-OS 11.1, upgrade to version 11.1.16-h2 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003col start=\"2\"\u003e\n\u003cli\u003eImplement network segmentation by restricting management interface access to a dedicated jump box or trusted management subnet to limit exposure.\u003c/li\u003e\n\u003cli\u003eIf Threat Prevention is licensed, enable Threat ID 510040 and 510041 and ensure appropriate SSL decryption is configured for inbound management traffic to facilitate inspection.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-09T18:58:48Z","date_published":"2026-09-09T18:58:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-panos-xss/","summary":"A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows an authenticated administrator to execute arbitrary JavaScript within the context of the management interface.","title":"CVE-2026-0308 Stored XSS in PAN-OS Web Interface","url":"https://feed.craftedsignal.io/briefs/2026-09-panos-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - PAN-OS (11.1.0 - 11.1.16)","version":"https://jsonfeed.org/version/1.1"}