Executive brief
A critical vulnerability exists in Palo Alto Networks PAN-OS firewalls that could allow an attacker to take full control of the device or shut it down. The issue affects the software's handling of secure VPN connections (IKEv2) when specific non-standard encryption settings are used. An exploit could lead to unauthorized access to the corporate network, data theft, or a total disruption of network services.
Technical details
A buffer overflow (CWE-787: Out-of-bounds Write) exists in the IKEv2 processing component of PAN-OS. The vulnerability is triggered when IKEv2 VPN tunnels are configured with non-NIST approved Post Quantum Cryptography (PQC) ciphers. An unauthenticated, network-based attacker can exploit this to achieve remote code execution (RCE) with elevated privileges or cause a system crash (DoS). While the CVSS 3.1 score is 9.8, the vendor notes that the attack complexity is high because it requires a specific non-default configuration. Fixed versions include 12.1.7, 12.1.4-h5, 11.2.12, 11.2.10-h6, 11.2.7-h13, 11.2.4-h17, 11.1.15, and other specific hotfixes.
Affected products
- Palo Alto Networks PAN-OS 12.1.0 to 12.1.4-h4, 12.1.5 to 12.1.6, 11.2.0 to 11.2.4-h16, 11.2.5 to 11.2.7-h12, 11.2.8 to 11.2.10-h5, 11.2.11, 11.1.0 to 11.1.4-h32, 11.1.5 to 11.1.6-h31, 11.1.7 to 11.1.7-h5, 11.1.8 to 11.1.10-h24, 11.1.11 to 11.1.13-h4, 11.1.14
Timeline
- 2026-05-13: advisory: Initial publication by Palo Alto Networks
- 2026-05-28: other: Advisory updated by vendor