PAN-OS
CVE-2026-0280: IPv6 Firewall Policy Bypass
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cloud NGFW | Not affected |
| PAN-OS 12.1 | 12.1.4-h8, 12.1.7-h2, 12.1.8 or later |
| PAN-OS 11.2 | 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, 11.2.13 or later |
| PAN-OS 11.1 | 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16 or later |
| PAN-OS 10.2 | 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8 or later |
| Panorama | Not affected |
| Prisma Access 11.2 | 11.2.7-h18 or later |
| Prisma Access 10.2 | 10.2.10-h39 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability.
Am I affected?
This issue applies to PAN-OS firewalls with IPv6 enabled on one or more interfaces.
You can verify IPv6 is enabled by checking: Network -> Interfaces -> [Interface with Layer3 type] -> IPv6 > Enable IPv6 on the interface
Workarounds
The only way to completely address this vulnerability is to upgrade to a fixed version. However, if operationally feasible for your environment, risk can be mitigated by enabling the default "Non SYN TCP Reject" setting via the following command:
set deviceconfig setting session tcp-reject-non-syn yes
Exploitation
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.