Skip to content
VulniPulse
High8.7Palo Alto Networks

High [CVE-2026-0229] denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software

This high-severity Palo Alto Networks advisory covers CVE-2026-0229 affecting PAN-OS, Prisma Access, Cloud NGFW.

CVE-2026-0229 Published Feb 11, 2026Updated by vendor Jun 17, 2026
Affected products & platforms
Palo Alto NetworksPAN-OSFirewallPrisma AccessCloud NGFWPAN-OS / Panorama
Open vendor advisory

Android app · Google Play

Monitor future Palo Alto Networks CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.

Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Affected versions
  • PAN-OS Firewall < 12.1.4
  • PAN-OS Firewall < 11.2.10

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • PAN-OS Firewall >= 12.1.4
  • PAN-OS Firewall >= 11.2.10

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • VersionMinor VersionSuggested SolutionCloud NGFW All No action needed.
  • PAN-OS 12.1 12.1.2 through 12.1.3 Upgrade to 12.1.4 or later.
  • PAN-OS 11.2 11.2.0 through 11.2.9 Upgrade to 11.2.10 or later.
  • PAN-OS 11.1No action needed.PAN-OS 10.2No action needed.All olderunsupportedPAN-OS versions Upgrade to a supported fixed version.Prisma Access AllNo action needed.
Temporary workarounds
  • No known workarounds exist for this issue.
  • Due to the nature of this vulnerability, a Threat Prevention Signature to detect this is also not possible.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.