Executive brief
Palo Alto Networks PAN-OS software, which powers corporate firewalls and cloud security services, is vulnerable to a flaw that allows an attacker to crash the device. By sending specifically malicious network traffic, an attacker can disrupt internet connectivity and security protections for the entire organization. Repeated attacks can force the firewall into a permanent maintenance mode, requiring manual intervention to restore service.
Technical details
Multiple denial of service (DoS) vulnerabilities exist in PAN-OS due to improper checks for unusual or exceptional conditions (CWE-754) during network traffic processing. An unauthenticated attacker can exploit these by sending specially crafted traffic to or through a dataplane interface. Successful exploitation causes a DoS condition, and repeated attempts can force the device into maintenance mode, necessitating manual recovery. The vulnerability affects PAN-OS, Cloud NGFW, and Prisma Access, though Prisma Access has a lower risk profile due to restricted dataplane access. Patches are available across multiple maintenance releases including 12.1.8, 11.2.13, 11.1.16, and 10.2.18-h8.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h8, 12.1.7-h2, 12.1.8; 11.2 < 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13; 11.1 < 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16; 10.2 < 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8
- Palo Alto Networks Cloud NGFW All versions on AWS and Azure
- Palo Alto Networks Prisma Access 11.2.0 < 11.2.7-h18; 10.2.0 < 10.2.10-h39
Timeline
- 2026-07-08: disclosed: Discovered internally by Palo Alto Networks
- 2026-07-08: advisory
- 2026-07-09: other: NVD publication date