Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop
A critical denial-of-service (DoS) vulnerability has been identified in Palo Alto Networks' PAN-OS software, potentially allowing unauthenticated attackers to cause firewalls to enter continuous reboot cycles. This flaw, designated as CVE-2026-0229,…
A critical denial-of-service (DoS) vulnerability has been identified in Palo Alto Networks' PAN-OS software, potentially allowing unauthenticated attackers to cause firewalls to enter continuous reboot cycles. This flaw, designated as CVE-2026-0229, resides within the Advanced DNS Security (ADNS) feature, where a specially crafted packet can trigger a system reboot.
Exploiting this vulnerability repeatedly forces the firewall into maintenance mode, disrupting traffic inspection and potentially leading to network outages. It is important to note that Cloud NGFW and Prisma Access products remain unaffected by this issue.
Palo Alto Networks has published a security advisory, indicating that this vulnerability impacts only specific PAN-OS versions when ADNS is enabled in conjunction with a spyware profile configured to block, sinkhole, or alert traffic.
Product Affected Versions Fixed Versions
PAN-OS 12.1 < 12.1.4 (specifically 12.1.2–12.1.3) ≥ 12.1.4
It is important to note that Cloud NGFW and Prisma Access products remain unaffected by this issue.
PAN-OS 11.2 < 11.2.10 (11.2.0–11.2.9) ≥ 11.2.10
PAN-OS 11.1 None All
PAN-OS 10.2 None All
Cloud NGFW None All
Prisma Access None All
Administrators are advised to upgrade affected systems promptly. Migration to a patched release is necessary for older, unsupported PAN-OS versions, as no workarounds are available. Due to the nature of the vulnerability, Threat Prevention signatures are unable to detect exploit attempts.
Palo Alto Networks reports no known exploitation of this vulnerability in the wild. However, security professionals highlight the risks in high-traffic environments. Firewalls utilizing ADNS are crucial in defending against DNS-based threats, and this vulnerability poses a significant risk to enterprises blocking malicious domains. Administrators should review configurations and assess systems for unpatched vulnerabilities via Palo Alto's support portal.
Based on reporting by Cyber Security News.
