Skip to content
All vulnerabilities
CVE-2026-0280

PAN-OS: IPv6 Firewall Policy Bypass

Severity
High7.2CVSS 3.1, High
EPSS
0.34%
Published
9 Jul 2026
Updated
11 Aug 2026

Description

Title, description and vendor guidance are quoted from the source records.

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

Weakness: CWE-131

Known exploited

Not listed in CISA KEV as of the last check.

Exploit prediction

0.34% probability of exploitation in the next 30 days (percentile 25%).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the source states, per branch

Versions matched by Patcharo

Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)

BranchAffectedFixed in
12.1
>= 12.1.0, < 12.1.4-h8
>= 12.1.5, < 12.1.7-h2
12.1.4-h8
12.1.7-h2
11.2
>= 11.2.0, < 11.2.4-h20
>= 11.2.5, < 11.2.7-h18
>= 11.2.8, < 11.2.10-h11
>= 11.2.11, < 11.2.13
11.2.4-h20
11.2.7-h18
11.2.10-h11
11.2.13
11.1
>= 11.1.0, < 11.1.4-h35
>= 11.1.5, < 11.1.6-h35
>= 11.1.7, < 11.1.7-h8
>= 11.1.8, < 11.1.10-h30
>= 11.1.11, < 11.1.13-h9
>= 11.1.14, < 11.1.16
11.1.4-h35
11.1.6-h35
11.1.7-h8
11.1.10-h30
11.1.13-h9
11.1.16
10.2
>= 10.2.0, < 10.2.7-h36
>= 10.2.8, < 10.2.10-h39
>= 10.2.11, < 10.2.13-h23
>= 10.2.14, < 10.2.16-h9
>= 10.2.17, < 10.2.18-h8
10.2.7-h36
10.2.10-h39
10.2.13-h23
10.2.16-h9
10.2.18-h8

Versions not listed are stated unaffected by the vendor.

Affected products

  • Palo Alto Networks Prisma Access · 11.2.0 < 11.2.7-h18, 10.2.0 < 10.2.10-h39

Workaround / Vendor remediation

Workaround · PAN-OS

The only way to completely address this vulnerability is to upgrade to a fixed version. However, if operationally feasible for your environment, risk can be mitigated by enabling the default "Non SYN TCP Reject" setting via the following command: set deviceconfig setting session tcp-reject-non-syn yes

Vendor remediation · PAN-OS

Version Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN-OS 11.2 11.2.11 through 11.2.12 Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h11 or 11.2.13 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later. PAN-OS 11.1 11.1.14 through 11.1.15 Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later. PAN-OS…

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
NVD
NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026, 02:31 UTC