Aller au contenu
Toutes les vulnérabilités
CVE-2026-0280

PAN-OS: IPv6 Firewall Policy Bypass

Sévérité
Élevée7,2CVSS 3.1, Élevée
EPSS
0,34 %
Publiée
9 juil. 2026
Mise à jour
11 août 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

Faiblesse : CWE-131

Exploitée activement

Non listée dans CISA KEV lors de la dernière vérification.

Prédiction d’exploitation

Probabilité d’exploitation de 0,34 % dans les 30 prochains jours (percentile 25 %).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Ce qu’indique la source, par branche

Versions comparées par Patcharo

Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)

BrancheAffectéesCorrigé en
12.1
>= 12.1.0, < 12.1.4-h8
>= 12.1.5, < 12.1.7-h2
12.1.4-h8
12.1.7-h2
11.2
>= 11.2.0, < 11.2.4-h20
>= 11.2.5, < 11.2.7-h18
>= 11.2.8, < 11.2.10-h11
>= 11.2.11, < 11.2.13
11.2.4-h20
11.2.7-h18
11.2.10-h11
11.2.13
11.1
>= 11.1.0, < 11.1.4-h35
>= 11.1.5, < 11.1.6-h35
>= 11.1.7, < 11.1.7-h8
>= 11.1.8, < 11.1.10-h30
>= 11.1.11, < 11.1.13-h9
>= 11.1.14, < 11.1.16
11.1.4-h35
11.1.6-h35
11.1.7-h8
11.1.10-h30
11.1.13-h9
11.1.16
10.2
>= 10.2.0, < 10.2.7-h36
>= 10.2.8, < 10.2.10-h39
>= 10.2.11, < 10.2.13-h23
>= 10.2.14, < 10.2.16-h9
>= 10.2.17, < 10.2.18-h8
10.2.7-h36
10.2.10-h39
10.2.13-h23
10.2.16-h9
10.2.18-h8

Selon l’éditeur, les versions non listées ne sont pas affectées.

Produits concernés

  • Palo Alto Networks Prisma Access · 11.2.0 < 11.2.7-h18, 10.2.0 < 10.2.10-h39

Contournement / Remédiation de l’éditeur

Contournement · PAN-OS

The only way to completely address this vulnerability is to upgrade to a fixed version. However, if operationally feasible for your environment, risk can be mitigated by enabling the default "Non SYN TCP Reject" setting via the following command: set deviceconfig setting session tcp-reject-non-syn yes

Remédiation de l’éditeur · PAN-OS

Version Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN-OS 11.2 11.2.11 through 11.2.12 Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h11 or 11.2.13 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later. PAN-OS 11.1 11.1.14 through 11.1.15 Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later. PAN-OS…

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC