PALO ALTO Security Advisory

Published Date: Not specified

CVE: CVE-2026-0309

Advisory Summary

🔍 📌 CVE-2026-0309 — PAN-OS Authenticated Command Injection (CLI) with Luna HSM Configuration

⚠️ Alarms
Palo Alto Networks has published details for CVE-2026-0309, describing an authenticated command injection issue in the PAN-OS CLI that is specifically tied to environments using Luna HSM configuration. While the severity is MEDIUM, command injection paths can still enable meaningful impact depending on privileges and the reachable CLI context.

🚨 Security Notes for Market Professionals
This advisory highlights a continuing theme: security issues in management/CLI surfaces can become exploitable when integration-specific configurations (like HSM) introduce additional logic paths. Operational teams should treat “authenticated” findings as still urgent when the management plane is reachable and accounts are valuable.

Informations: For exact affected versions, mitigations (if any), and upgrade guidance, follow Palo Alto Networks’ advisory link.

Reference: Vendor Advisory