Are you planning to upgrade Panorama managed Paloalto firewall? Is your Paloalto forwarding samples to on-prem Wildfire appliance? If yes, you need to know few pre-requisite before upgrading firewall.
When upgrading firewalls that you manage with Panorama or firewalls that are configured to forward content to a WildFire appliance, you must first upgrade Panorama and its Log Collectors and then upgrade the WildFire appliance before you upgrade the firewalls.

Panorama version should be equal or higher then firewall target version. Same applies to Wildfire with regards to firewall. Additionally, it is not recommended to manage firewalls running a later maintenance release than Panorama as this may result in features not working as expected. For example, it is not recommended to manage firewalls running PAN-OS 11.1.1 or later maintenance releases if Panorama is running PAN-OS 11.1.0.