PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Plan PatchCVSS 8.7CVE-2026-0287Jul 8, 2026
Palo Alto NetworksTransportation
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access allow an unauthenticated attacker with network access to cause a denial of service condition by sending specially crafted network traffic to a dataplane interface. Repeated attempts trigger the firewall to enter maintenance mode, stopping all traffic processing. Panorama is not impacted.

What this means
What could happen
An attacker can send specially crafted network traffic through the firewall to cause it to stop processing traffic and enter maintenance mode, disrupting all network communication and dependent operations.
Who's at risk
Transportation companies and any organizations relying on Palo Alto Networks firewalls for network security, including those using PAN-OS on-premises appliances, Cloud NGFW on AWS or Azure, or Prisma Access remote access solutions. Any environment where traffic through the firewall is critical to operations is at risk.
How it could be exploited
An attacker with network access to any dataplane interface sends specially crafted packets designed to trigger the denial of service condition. Repeated crafted traffic forces the firewall into maintenance mode, halting all traffic processing and operational continuity.
Prerequisites
  • Network access to a dataplane interface (WAN, LAN, or any monitored network segment)
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects network availability and operational continuity
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (9)
7 with fix2 pending
ProductAffected VersionsFix Status
Cloud NGFWAll on AWSNo fix yet
Cloud NGFWAll on AzureNo fix yet
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.4-h2011.2.4-h20+
Prisma AccessBelow 11.2.7-h1811.2.7-h18+
Prisma AccessBelow 11.2.10-h1211.2.10-h12+
Remediation & Mitigation
0/4
Do now
0/1
Cloud NGFW
WORKAROUNDMigrate Cloud NGFW deployments on AWS and Azure to non-vulnerable infrastructure or behind additional rate-limiting controls while fix is pending
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.4-h8, 12.1.7-h2, or 12.1.8 or later depending on current branch
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, or 11.2.13 or later depending on current branch
Long-term hardening
0/1
HARDENINGRestrict dataplane interface access using network segmentation and ACLs to limit exposure from untrusted networks
API: /api/v1/advisories/c8e54fc1-bd22-4711-9a9a-f37b4bd4989b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing | CVSS 8.7 - OTPulse