vulnerability
Palo Alto Networks PAN-OS: CVE-2026-0256: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:N/AC:M/Au:M/C:P/I:C/A:N) | May 13, 2026 | May 18, 2026 | May 18, 2026 |
Severity
6
CVSS
(AV:N/AC:M/Au:M/C:P/I:C/A:N)
Published
May 13, 2026
Added
May 18, 2026
Modified
May 18, 2026
Description
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Solution
palo-alto-networks-pan-os-upgrade-latest
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.