Junglewise Threat Intelligence

CVE-2026-0280: Palo Alto Networks PAN-OS IPv6 security policy bypass in dataplane

CVE-2026-0280 · Severity: info · CVSS 1.7 · Published 2026-07-09

Technologies: Palo Alto Networks Prisma Access. Vendors: Palo Alto Networks.

Executive brief

A vulnerability in Palo Alto Networks firewalls could allow an unauthorized person to bypass security rules when using IPv6 networking. This means network traffic that is supposed to be blocked might reach internal protected services. This issue only affects devices where IPv6 is specifically enabled on one or more network interfaces.

Technical details

An incorrect calculation of buffer size (CWE-131) in the PAN-OS dataplane's IPv6 packet processing logic allows for a security policy bypass. An unauthenticated network-based attacker can exploit this to send traffic to protected services that should otherwise be restricted by firewall rules. The vulnerability requires IPv6 to be enabled on at least one interface to be exploitable. Palo Alto Networks has released patches for affected versions of PAN-OS and Prisma Access, and a mitigation exists by enabling the 'Non SYN TCP Reject' setting.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h8, 12.1.5 to 12.1.7-h2, 11.2 < 11.2.4-h20, 11.2.5 to 11.2.7-h18, 11.2.8 to 11.2.10-h11, 11.2.11 to 11.2.13, 11.1 < 11.1.16, 10.2 < 10.2.18-h8
  • Palo Alto Networks Prisma Access 11.2.0 < 11.2.7-h18, 10.2.0 < 10.2.10-h39

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-09: patched

References

Related threats