PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0256 Palo Alto Networks CVE debrief

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Vendor
Palo Alto Networks
Product
Cloud NGFW
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-06-09
Advisory published
2026-05-13
Advisory updated
2026-06-09

Who should care

Administrators and users of Palo Alto Networks PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series) should be aware of this vulnerability.

Technical summary

The vulnerability has a CVSS score of 4.4 and a severity of MEDIUM. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply the patch or update provided by Palo Alto Networks to fix the vulnerability.
  • Restrict access to the web interface to prevent malicious administrators from storing JavaScript payloads.

Evidence notes

The vendor is Palo Alto Networks, as indicated by the evidence from reference_domain_candidate.

Official resources

CVE-2026-0256 was published on 2026-05-13T19:17:00.603Z and modified on 2026-06-09T10:16:39.507Z.