Palo Alto Networks Firewall Vulnerability Allows Attacker to Trigger DoS Attacks
Palo Alto Networks has addressed a critical denial-of-service vulnerability in its PAN-OS firewall software, identified as CVE-2026-0227. This vulnerability allows unauthenticated attackers to disrupt GlobalProtect gateways and portals.
Palo Alto Networks has addressed a critical denial-of-service vulnerability in its PAN-OS firewall software, identified as CVE-2026-0227. This vulnerability allows unauthenticated attackers to disrupt GlobalProtect gateways and portals.
The vulnerability has a CVSS v4.0 base score of 7.7, classified as high severity. It arises from improper checks for unusual conditions, which can force firewalls into maintenance mode following repeated exploitation attempts. The issue affects multiple PAN-OS versions but does not impact the Cloud NGFW.
The vulnerability is exploitable over the network with low complexity, requiring no privileges or user interaction, making it automatable and highly feasible. It aligns with CWE-754 (Improper Check for Unusual or Exceptional Conditions) and CAPEC-210 (Abuse Existing Functionality), significantly impacting product availability while leaving confidentiality and integrity unaffected.
Palo Alto Networks has addressed a critical denial-of-service vulnerability in its PAN-OS firewall software, identified as CVE-2026-0227.
PAN-OS 12.1: Affected versions include < 12.1.3-h3, < 12.1.4. Unaffected versions are >= 12.1.3-h3, >= 12.1.4. PAN-OS 11.2: Affected versions include < 11.2.4-h15, < 11.2.7-h8, < 11.2.10-h2. Unaffected versions are >= 11.2.4-h15 (ETA: Jan 14, 2026), >= 11.2.7-h8, >= 11.2.10-h2. PAN-OS 11.1: Affected versions include < 11.1.4-h27, < 11.1.6-h23, < 11.1.10-h9, < 11.1.13. Unaffected versions are >= 11.1.4-h27, >= 11.1.6-h23, >= 11.1.10-h9, >= 11.1.13. PAN-OS 10.2: Affected versions include < 10.2.7-h32, < 10.2.10-h30, < 10.2.13-h18, < 10.2.16-h6, < 10.2.18-h1. Unaffected versions are >= 10.2.7-h32, >= 10.2.10-h30, >= 10.2.13-h18, >= 10.2.16-h6, >= 10.2.18-h1. PAN-OS 10.1: Affected versions include < 10.1.14-h20. Unaffected versions are >= 10.1.14-h20. Prisma Access 11.2: Affected versions include < 11.2.7-h8*. Unaffected versions are >= 11.2.7-h8*. Prisma Access 10.2: Affected versions include < 10.2.10-h29*. Unaffected versions are >= 10.2.10-h29*.
Administrators are advised to upgrade to the latest hotfixes, such as PAN-OS 12.1.4 or 11.2.10-h2, as no workarounds are available. The response effort is moderate and involves user-led recovery. Organizations should verify configurations via Palo Alto's support portal and monitor for potential denial-of-service attempts.
For more information, visit the Palo Alto Networks Security Advisory .
Based on reporting by Cyber Security News.
