Junglewise Threat Intelligence

CVE-2026-0269: Palo Alto Networks PAN-OS memory corruption in tunnel traffic processing

CVE-2026-0269 · Severity: info · CVSS 4.6 · Published 2026-06-10

Vendors: Palo Alto Networks.

Executive brief

A vulnerability in Palo Alto Networks firewalls could allow an authorized user to restart the device by sending a specifically crafted network packet. If the device is restarted multiple times, it may enter a maintenance mode that disrupts all network traffic and security services. This issue specifically affects firewalls configured with IPSec Tunnels or GlobalProtect Gateways.

Technical details

A memory corruption vulnerability (CWE-754) exists in the tunnel traffic processing component of Palo Alto Networks PAN-OS. An authenticated attacker with network access to the device's tunnel interfaces (IPSec or GlobalProtect) can send maliciously crafted packets to trigger a system reboot. Repeated exploitation can force the device into maintenance mode, resulting in a sustained denial-of-service (DoS) condition. The vulnerability affects various versions of PAN-OS 10.2, 11.1, 11.2, and 12.1. Patches are available in versions 12.1.4-h5, 11.2.10, 11.1.12, 10.2.18, and other specific hotfix releases.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1 < 12.1.5, 11.2 < 11.2.4-h17, 11.2 < 11.2.7-h4, 11.2 < 11.2.10, 11.1 < 11.1.4-h33, 11.1 < 11.1.6-h21, 11.1 < 11.1.10-h7, 11.1 < 11.1.12, 10.2 < 10.2.7-h34, 10.2 < 10.2.10-h36, 10.2 < 10.2.13-h21, 10.2 < 10.2.16-h6, 10.2 < 10.2.18

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References