Executive brief
Palo Alto Networks PAN-OS is the operating system used by corporate firewalls to secure network traffic. Multiple vulnerabilities allow an unauthenticated attacker to crash the firewall by sending specifically designed network traffic to its data interfaces. This results in a denial-of-service condition, potentially cutting off network connectivity or security protections for the organization.
Technical details
The vulnerability is classified as an improper check for unusual or exceptional conditions (CWE-754) within the network traffic parsing component of PAN-OS. An unauthenticated attacker can exploit this by sending specially crafted network traffic to a dataplane interface. Successful exploitation results in a denial-of-service (DoS) condition. The issue affects various versions of PAN-OS 10.2, 11.1, 11.2, and 12.1, as well as Siemens RUGGEDCOM APE1808 devices running Virtual NGFW. Panorama, Cloud NGFW, and Prisma Access are not impacted. Patches are available in updated maintenance releases (e.g., 12.1.7, 11.2.12, 11.1.15, 10.2.18-h6).
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1 < 12.1.7, 11.2 < 11.2.4-h17, 11.2 < 11.2.7-h13, 11.2 < 11.2.10-h6, 11.2 < 11.2.12, 11.1 < 11.1.4-h33, 11.1 < 11.1.6-h32, 11.1 < 11.1.7-h6, 11.1 < 11.1.10-h25, 11.1 < 11.1.13-h5, 11.1 < 11.1.15, 10.2 < 10.2.7-h34, 10.2 < 10.2.10-h36, 10.2 < 10.2.13-h21, 10.2 < 10.2.16-h7, 10.2 < 10.2.18-h6
- Siemens RUGGEDCOM APE1808 Virtual NGFW All versions
Timeline
- 2026-05-12: advisory: Initial Siemens advisory published
- 2026-05-13: advisory: Palo Alto Networks advisory published
- 2026-05-15: patched: Prisma Access upgraded for all customers
- 2026-05-28: other: Advisory updated by vendor