PAN-OS
CVE-2026-0287: Denial of Service Vulnerabilities in Network Traffic Processing
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cloud NGFW (AWS, Azure) | See the advisory |
| PAN-OS 12.1 | 12.1.4-h8, 12.1.7-h2, 12.1.8 or later |
| PAN-OS 11.2 | 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13 or later |
| PAN-OS 11.1 | 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16 or later |
| PAN-OS 10.2 | 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8 or later |
| Prisma Access 11.2 | 11.2.7-h18 or later |
| Prisma Access 10.2 | 10.2.10-h39 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
Panorama is not impacted by these vulnerabilities.
Am I affected?
No special configuration is required to be affected by this issue.
Workarounds
No known workarounds exist for this issue.
Exploitation
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.