Skip to content
Palo Alto NetworksCVE-2026-0287

Palo Alto Networks Cloud NGFW: denial of service

Medium6.6CVE-2026-0287 · Published Jul 9, 2026 · updated Aug 11, 2026

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.

Palo Alto Networks advisory

Affected versions

PackageAffectedFixed in
Cloud NGFW
Product
all versionsNo fix yet
PAN-OS
Product
>= 12.1.0, < 12.1.4-h812.1.4-h8
>= 11.2.0, < 11.2.4-h2011.2.4-h20
>= 11.1.0, < 11.1.4-h3511.1.4-h35
>= 10.2.0, < 10.2.7-h3610.2.7-h36
Prisma Access
Product
>= 11.2.0, < 11.2.7-h1811.2.7-h18
>= 10.2.0, < 10.2.10-h3910.2.10-h39
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-754

More Palo Alto Networks advisories

All Palo Alto Networks
Advisory
Palo Alto Networks Prisma Browser: privilege escalation
Low2.0Jul 9
Palo Alto Networks Cortex XDR Broker VM: privilege escalation
Low1.1Jul 9
Palo Alto Networks Prisma Access Agent: improper certificate validation
Medium5.7Jul 9
Palo Alto Networks Prisma: local user could bypass DLP policy enforcement...
Medium5.8Jul 9
Palo Alto Networks PAN-OS: command injection
Medium6.0Jul 9
Palo Alto Networks PAN-OS: information disclosure
Medium4.7Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.