CVE-2026-0308EPSS p16.8%
CVE-2026-0308CVE-2026-0308
Description
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Scoring
| EPSS | 0.27% probability of exploitation · percentile 16.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-10 |