vulnerability

Palo Alto Networks PAN-OS: CVE-2026-0256: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Severity
6
CVSS
(AV:N/AC:M/Au:M/C:P/I:C/A:N)
Published
May 13, 2026
Added
May 18, 2026
Modified
May 18, 2026

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Solution

palo-alto-networks-pan-os-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.