Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-0264

CVE-2026-0264: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityCritical9.2

    Critical [CVE-2026-0264] PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

    CVE-2026-0264Source published

    CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

    Affected products in this advisory
    • PAN-OS
    Source-reported affected versions
    • PAN-OS 12.1: < 12.1.4-h5< 12.1.7
    • PAN-OS 11.2: < 11.2.4-h17< 11.2.7-h13< 11.2.10-h6< 11.2.12
    • PAN-OS 11.1: < 11.1.4-h33< 11.1.6-h32< 11.1.7-h6< 11.1.10-h25< 11.1.13-h5< 11.1.15
    • PAN-OS 10.2: < 10.2.7-h34< 10.2.10-h36< 10.2.13-h21< 10.2.16-h7< 10.2.18-h6
    Source-reported fixed versions
    • PAN-OS >= 12.1.4-h5
    • PAN-OS >= 12.1.7
    • PAN-OS >= 11.2.4-h17
    • PAN-OS >= 11.2.7-h13

    13 more entries in the full advisory.

    Mitigation guidance
    • All older unsupported PAN-OS versions Upgrade to a supported fixed version.
    Workarounds
    • Customers can mitigate the risk of this issue by taking either of the following actions:Action 1:
    • Disassociate DNS Proxy from externally accessible interfaces in order to reduce your attack surface; ANDConfigure DNS server with a RFC1918 or a public trusted IP address.
    • Disable the DNS Proxy feature (Network > DNS Proxy) if it is not being used; ANDConfigure DNS server with a RFC1918 or a public trusted IP address.
    • Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510027 from Applications and Threats content version 9100-10044 and later.

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery