Palo Alto Networks Firewall Vulnerability Allows Attackers To Trigger Denial Of Service
Palo Alto Networks has issued security updates to rectify a high-severity denial-of-service (DoS) vulnerability identified in PAN-OS. This flaw may enable unauthenticated attackers to repeatedly crash firewalls configured with GlobalProtect, forcing them…
Palo Alto Networks has issued security updates to rectify a high-severity denial-of-service (DoS) vulnerability identified in PAN-OS. This flaw may enable unauthenticated attackers to repeatedly crash firewalls configured with GlobalProtect, forcing them into maintenance mode and disrupting network availability.
The vulnerability, designated as CVE-2026-0227, has a CVSS Base score of 8.7. It affects both on-premises PAN-OS next-generation firewalls (NGFW) and Prisma Access deployments with GlobalProtect gateway or portal enabled.
DoS Flaw in GlobalProtect Gateway and Portal
According to Palo Alto Networks, CVE-2026-0227 is due to an improper check for unusual or exceptional conditions in the PAN-OS implementation of the GlobalProtect gateway and portal. This maps to CWE-754 and CAPEC-210 (Abuse Existing Functionality).
An unauthenticated remote attacker can exploit this logic flaw over the network to trigger a DoS condition, causing the targeted firewall to stop processing traffic. Repeated exploitation may cause the firewall to enter maintenance mode, requiring administrative intervention to resume normal operations.
This issue is present only when a PAN-OS NGFW or Prisma Access tenant has an active GlobalProtect gateway or portal. Environments not using GlobalProtect are not affected by this specific vulnerability.
Palo Alto Networks has issued security updates to rectify a high-severity denial-of-service (DoS) vulnerability identified in PAN-OS.
No malicious exploitation in the wild has been reported, although a proof-of-concept (PoC) exploit exists. The severity is categorized as HIGH, with a "MODERATE" suggested urgency under its CVSS 4.0 breakdown (CVSS-BT 7.7 / CVSS-B 8.7).
Affected Versions, Fixes, and Guidance
The vulnerability impacts multiple versions of PAN-OS 10.1, 10.2, 11.1, 11.2, and 12.1 branches, while Cloud NGFW is listed as unaffected.
Affected PAN-OS versions: 12.1.0–12.1.3 (before hotfix h3), 11.2.0–11.2.10 (before hotfix levels 11.2.4-h15, 11.2.7-h8, 11.2.10-h2), 11.1.0–11.1.12 (before hotfixes 11.1.4-h27, 11.1.6-h23, 11.1.10-h9, 11.1.13), 10.2.0–10.2.18 (before fixed builds 10.2.7-h32, 10.2.10-h30, 10.2.13-h18, 10.2.16-h6, 10.2.18-h1), and PAN-OS 10.1 (earlier than 10.1.14-h20).
Prisma Access tenants are vulnerable on 11.2 prior to 11.2.7-h8 and 10.2 prior to 10.2.10-h29. Most customers have already been upgraded, and remaining tenants are scheduled for updates via the standard upgrade process.
Palo Alto Networks recommends upgrading to the nearest fixed PAN-OS maintenance release. For example, users of 12.1.0–12.1.3 should upgrade to 12.1.4 or later, 11.2.8–11.2.10 to 11.2.10-h2 or later, and 10.2.17–10.2.18 to 10.2.18-h1 or later. Older unsupported PAN-OS versions should be upgraded to a supported fixed train.
There are no workarounds or mitigations available. Organizations running GlobalProtect gateways or portals on affected PAN-OS or Prisma Access versions should prioritize patching to prevent attackers from exploiting this DoS flaw, which could disable perimeter firewalls and cause significant disruption.
Based on reporting by GBHackers.
