PAN-OS

CVE-2026-0280: IPv6 Firewall Policy Bypass

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityLOWCVSS 4.0 6.3
EPSS0.34%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Cloud NGFWNot affected
PAN-OS 12.112.1.4-h8, 12.1.7-h2, 12.1.8 or later
PAN-OS 11.211.2.4-h20, 11.2.7-h18, 11.2.10-h11, 11.2.13 or later
PAN-OS 11.111.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16 or later
PAN-OS 10.210.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8 or later
PanoramaNot affected
Prisma Access 11.211.2.7-h18 or later
Prisma Access 10.210.2.10-h39 or later

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.

Cloud NGFW and Panorama are not impacted by this vulnerability.

Am I affected?

This issue applies to PAN-OS firewalls with IPv6 enabled on one or more interfaces.

You can verify IPv6 is enabled by checking: Network -> Interfaces -> [Interface with Layer3 type] -> IPv6 > Enable IPv6 on the interface

Workarounds

The only way to completely address this vulnerability is to upgrade to a fixed version. However, if operationally feasible for your environment, risk can be mitigated by enabling the default "Non SYN TCP Reject" setting via the following command:

set deviceconfig setting session tcp-reject-non-syn yes

Exploitation

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.