High [CVE-2026-0287] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
This high-severity Palo Alto Networks advisory covers CVE-2026-0287 affecting Cloud NGFW, PAN-OS, Prisma Access.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Palo Alto Networks CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
Panorama is not impacted by these vulnerabilities.
Affected products named by the advisory: Cloud NGFW; Prisma Access.
- Cloud NGFW All
- PAN-OS < 12.1.4-h8
- PAN-OS < 11.2.4-h20
- PAN-OS < 11.1.4-h35
- PAN-OS < 10.2.7-h36
- Prisma Access < 11.2.7-h18
- Prisma Access < 10.2.10-h39
Official advisory · high-confidence parse· fetched 27 days ago·verify at source
- PAN-OS >= 12.1.4-h8
- PAN-OS >= 12.1.7-h2
- PAN-OS >= 12.1.8
- PAN-OS >= 11.2.4-h20
- PAN-OS >= 11.2.7-h18
- PAN-OS >= 11.2.10-h12
- PAN-OS >= 11.2.13
- PAN-OS >= 11.1.4-h35
- PAN-OS >= 11.1.6-h35
- PAN-OS >= 11.1.7-h8
- PAN-OS >= 11.1.10-h30
- PAN-OS >= 11.1.13-h9
- PAN-OS >= 11.1.16
- PAN-OS >= 10.2.7-h36
- PAN-OS >= 10.2.10-h39
- PAN-OS >= 10.2.13-h23
- PAN-OS >= 10.2.16-h9
- PAN-OS >= 10.2.18-h8
- Prisma Access >= 11.2.7-h18
- Prisma Access >= 10.2.10-h39
Official advisory · high-confidence parse· fetched 27 days ago·verify at source
Mitigation checklist
- Upgrade to a fixed release: PAN-OS >= 12.1.4-h8; PAN-OS >= 12.1.7-h2; PAN-OS >= 12.1.8; PAN-OS >= 11.2.4-h20; ….
- No known workarounds exist for this issue.
Official advisory · high-confidence parse· fetched 27 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.