CVE-2026-0287High· 7.5▾ TwilightMultiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or throu…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.6%
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
Panorama is not impacted by these vulnerabilities.
cloud_ngfwpan-os >= 10.2.0, < 10.2.7pan-os >= 10.2.8, < 10.2.10pan-os >= 10.2.11, < 10.2.13pan-os >= 10.2.14, < 10.2.16pan-os = 10.2.7pan-os = 10.2.10pan-os = 10.2.13pan-os = 10.2.16pan-os = 10.2.17pan-os = 10.2.18pan-os >= 11.1.0, < 11.1.4pan-os >= 11.1.8, < 11.1.10pan-os >= 11.1.11, < 11.1.13pan-os >= 11.1.14, < 11.1.16pan-os = 11.1.4pan-os = 11.1.5pan-os = 11.1.6pan-os = 11.1.10pan-os = 11.1.13pan-os >= 11.2.0, < 11.2.4pan-os >= 11.2.5, < 11.2.7pan-os >= 11.2.8, < 11.2.10pan-os >= 11.2.11, < 11.2.13pan-os = 11.2.4pan-os = 11.2.7pan-os = 11.2.10pan-os >= 12.1.2, < 12.1.4pan-os >= 12.1.5, < 12.1.7pan-os = 12.1.4pan-os = 12.1.7Upgrade past the affected range:
pan-os 12.1.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0241High· 7.2Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.
CVE-2026-0269Medium· 5.7A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet
CVE-2026-0295High· 7.0A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…
CVE-2026-0289Medium· 6.5A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.
CVE-2026-0292Medium· 6.0An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…
CVE-2026-0290Medium· 5.5An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.