Critical [CVE-2026-0263] PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
This critical-severity Palo Alto Networks advisory covers CVE-2026-0263 affecting PAN-OS.
Android app · Google Play
Monitor future Palo Alto Networks CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
- PAN-OS 12.1: < 12.1.4-h5< 12.1.7
- PAN-OS 11.2: < 11.2.4-h17< 11.2.7-h13< 11.2.10-h6< 11.2.12
- PAN-OS 11.1: < 11.1.4-h33< 11.1.6-h32< 11.1.7-h6< 11.1.10-h25< 11.1.13-h5< 11.1.15
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
- PAN-OS >= 12.1.7
- PAN-OS >= 12.1.4-h5
- PAN-OS >= 11.2.12
- PAN-OS >= 11.2.10-h6
- PAN-OS >= 11.2.7-h13
- PAN-OS >= 11.2.4-h17
- PAN-OS >= 11.1.15
- PAN-OS >= 11.1.13-h5
- PAN-OS >= 11.1.10-h25
- PAN-OS >= 11.1.7-h6
- PAN-OS >= 11.1.6-h32
- PAN-OS >= 11.1.4-h33
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Mitigation checklist
- All older unsupported PAN-OS versions Upgrade to a supported fixed version.
- Customers using IKEv2 VPN can mitigate this issue by configuring IKEv2 VPN tunnels only with NIST approved Post Quantum Cryptography (PQC) ciphers.
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.