---
id: CVE-2026-0269
title: >-
  A memory corruption vulnerability in the processing of tunnel traffic in Palo
  Alto Networks PAN-OS® software allows an authenticated user to initiate system
  reboots using a maliciously crafted packet
summary: >-
  A memory corruption vulnerability in the processing of tunnel traffic in Palo
  Alto Networks PAN-OS® software allows an authenticated user to initiate system
  reboots using a maliciously crafted packet. Repeated attempts to initiate a
  rebo…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-754
vendor: paloaltonetworks
product: pan-os
affected:
  - 'pan-os >= 10.2.0, < 10.2.7'
  - 'pan-os >= 10.2.8, < 10.2.10'
  - 'pan-os >= 10.2.11, < 10.2.13'
  - 'pan-os >= 10.2.14, < 10.2.16'
  - pan-os = 10.2.7
  - pan-os = 10.2.10
  - pan-os = 10.2.13
  - pan-os = 10.2.16
  - pan-os = 10.2.17
  - 'pan-os >= 11.1.0, < 11.1.4'
  - 'pan-os >= 11.1.5, < 11.1.6'
  - 'pan-os >= 11.1.7, < 11.1.10'
  - pan-os = 11.1.4
  - pan-os = 11.1.6
  - pan-os = 11.1.10
  - pan-os = 11.1.11
  - 'pan-os >= 11.2.0, < 11.2.4'
  - 'pan-os >= 11.2.5, < 11.2.7'
  - 'pan-os >= 11.2.8, < 11.2.10'
  - pan-os = 11.2.4
  - pan-os = 11.2.7
  - 'pan-os >= 12.1.0, < 12.1.4'
  - pan-os = 12.1.4
patched:
  - pan-os 12.1.4
published: '2026-06-10'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0269'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0269'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00224
epssPercentile: 0.11542
ingestedAt: '2026-07-13T13:27:18.091Z'
---

## Overview

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.



Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

## Affected

- `pan-os >= 10.2.0, < 10.2.7`
- `pan-os >= 10.2.8, < 10.2.10`
- `pan-os >= 10.2.11, < 10.2.13`
- `pan-os >= 10.2.14, < 10.2.16`
- `pan-os = 10.2.7`
- `pan-os = 10.2.10`
- `pan-os = 10.2.13`
- `pan-os = 10.2.16`
- `pan-os = 10.2.17`
- `pan-os >= 11.1.0, < 11.1.4`
- `pan-os >= 11.1.5, < 11.1.6`
- `pan-os >= 11.1.7, < 11.1.10`
- `pan-os = 11.1.4`
- `pan-os = 11.1.6`
- `pan-os = 11.1.10`
- `pan-os = 11.1.11`
- `pan-os >= 11.2.0, < 11.2.4`
- `pan-os >= 11.2.5, < 11.2.7`
- `pan-os >= 11.2.8, < 11.2.10`
- `pan-os = 11.2.4`
- `pan-os = 11.2.7`
- `pan-os >= 12.1.0, < 12.1.4`
- `pan-os = 12.1.4`

## Remediation

Upgrade past the affected range:

- `pan-os 12.1.4`
