CVE-2026-0269

PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

Severity
Medium 4.6
CVSS 4.0
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
11.8th percentile
Discovered by
Customer
Vendor-published field
Published
Jun 10, 2026
Assigned by palo_alto

Description

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Weakness: CWE-754

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Check your version Firewall / NGFW cna-assigner
Vendor-reported products (5)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Panorama — vendor states not affected
  • Palo Alto Networks · Prisma Access — vendor states not affected
  • Siemens · RUGGEDCOM APE1808

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h5 or 12.1.5 or later. PAN-OS 11.2 11.2.8 through 11.2.9 Upgrade to 11.2.10 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h4 or 11.2.10 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h17 or 11.2.10 or later. PAN-OS 11.1 11.1.11 or later Upgrade to 11.1.12 or later.   11.1.7 through 11.1.10-h* Upgrade to 11.1.10-h7 or 11.1.12 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h21 or 11.1.12 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h33 or 11.1.12 or later. PAN-OS 10.2 10.2.17 or later Upgrade to 10.2.18 or later.   10.2.4 through 10.2.16-h* Upgrade to 10.2.16-h6 or 10.2.18 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h21 or 10.2.18 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h36 or 10.2.18 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h34 or 10.2.18 or later. All older   Upgrade to a supported fixed version. unsupported PAN-OS versions Panorama   No action needed. Prisma Access No action needed.

Something wrong here?