PAN-OS: IPv6 Firewall Policy Bypass

MonitorCVSS 6.3CVE-2026-0280Jul 8, 2026
Palo Alto NetworksTransportation
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

What this means
What could happen
An attacker could craft malicious IPv6 packets to bypass firewall security policies, allowing blocked network traffic to reach protected systems and services.
Who's at risk
Transportation organizations using Palo Alto Networks PAN-OS firewalls with IPv6 enabled should review their firewall configurations. This affects network perimeter security for facilities that rely on PAN-OS firewalls to protect their operational networks, including control system networks and critical data systems.
How it could be exploited
An attacker sends specially crafted IPv6 packets across the network to your firewall. The firewall's dataplane IPv6 packet processing fails to apply the configured security policies, so traffic that should be blocked passes through to protected systems on the other side.
Prerequisites
  • IPv6 traffic enabled on the firewall
  • Attacker able to send IPv6 packets to or through the firewall
remotely exploitableno authentication requiredfirewall policy bypassIPv6 traffic
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (13)
13 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
PanoramaBelow 11.2.4-h2011.2.4-h20+
PanoramaBelow 11.2.7-h1811.2.7-h18+
PanoramaBelow 11.2.10-h1111.2.10-h11+
PanoramaBelow 11.2.1311.2.13+
Prisma AccessBelow 11.1.4-h3511.1.4-h35+
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDAs an immediate interim measure, enable Non SYN TCP Reject on the firewall by running: set deviceconfig setting session tcp-reject-non-syn yes
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpgrade PAN-OS to 12.1.4-h8, 12.1.7-h2, or 12.1.8 depending on your current version line
Panorama
HOTFIXUpgrade Panorama to 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, or 11.2.13 depending on your current version line
Prisma Access
HOTFIXUpgrade Prisma Access to 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, or 11.1.16 depending on your current version line
API: /api/v1/advisories/43d8b5f8-f7c7-4044-b308-e9c26af873e7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.