Skip to content
All vulnerabilities
CVE-2026-0227

PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

Severity
High7.5CVSS 3.1, High
EPSS
0.75%
Published
15 Jan 2026
Updated
17 Jun 2026

Description

Title, description and vendor guidance are quoted from the source records.

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

Weakness: CWE-754

Known exploited

Not listed in CISA KEV as of the last check.

Exploit prediction

0.75% probability of exploitation in the next 30 days (percentile 53%).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the source states, per branch

Versions matched by Patcharo

Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)

BranchAffectedFixed in
12.1
>= 12.1.2, < 12.1.3-h3
12.1.3-h3
11.2
>= 11.2.0, < 11.2.4-h15
>= 11.2.5, < 11.2.7-h8
>= 11.2.8, < 11.2.10-h2
11.2.4-h15
11.2.7-h8
11.2.10-h2
11.1
>= 11.1.0, < 11.1.4-h27
>= 11.1.5, < 11.1.6-h23
>= 11.1.7, < 11.1.10-h9
>= 11.1.11, < 11.1.13
11.1.4-h27
11.1.6-h23
11.1.10-h9
11.1.13
10.2
>= 10.2.0, < 10.2.7-h32
>= 10.2.8, < 10.2.10-h30
>= 10.2.11, < 10.2.13-h18
>= 10.2.14, < 10.2.16-h6
>= 10.2.17, < 10.2.18-h1
10.2.7-h32
10.2.10-h30
10.2.13-h18
10.2.16-h6
10.2.18-h1
10.1
>= 10.1.0, < 10.1.14-h20
10.1.14-h20

Versions not listed are not assessed (shown as Unknown).

Affected products

  • Palo Alto Networks Prisma Access · 11.2 < 11.2.7-h8, 10.2 < 10.2.10-h29, 10.2.4-h43

Workaround / Vendor remediation

Workaround · PAN-OS

No known workarounds exist for this issue.

Vendor remediation · PAN-OS

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All No action needed. PAN-OS 12.1 12.1.2 through 12.1.3 Upgrade to 12.1.4 or later. PAN-OS 11.2 11.2.8 through 11.2.10 Upgrade to 11.2.10-h2 or later. 11.2.5 through 11.2.7 Upgrade to 11.2.7-h8 or 11.2.10-h2 or later. 11.2.0 through 11.2.4 Upgrade to 11.2.4-h15 or 11.2.10-h2 or later. PAN-OS 11.1 11.1.11 through 11.1.12 Upgrade to 11.1.13 or later. 11.1.7 through 11.1.10 Upgrade to 11.1.10-h9 or 11.1.13 later. 11.1.5 through 11.1.6 Upgrade to 11.1.6-h23 or 11.1.13 or later. 11.1.0 through 11.1.4 Upgrade to 11.1.4-h27 or 11.1.13 or later. PAN-OS 10.2 10.2.17 through 10.2.18 Upgrade to 10.2.18-h1 or later. 10.2.14 through 10.2.16 Upgrade to 10.2.16-h6 or 10.2.18-h1 or later. 10.2.11 through 10.2.13 Upgrade to 10.2.13-h18 or 10.2.18-h1 or later. 10.2.8 through 10.2.10 Upgrade to 10.2.10-h30 or 10.2.18-h1 or later. 10.2.0 through 10.2.7 Up…

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
NVD
NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026, 02:31 UTC