HIGH 7.5

CVE-2026-0287: Palo Alto Networks PAN-OS Denial of Service Vulnerability – Risk Assessment

Palo Alto Networks PAN-OS firewalls contain multiple denial of service vulnerabilities that allow unauthenticated attackers on the network to crash the firewall by sending specially crafted traffic through dataplane interfaces. Repeating this attack forces the firewall into maintenance mode, effectively taking it offline. Panorama management systems are not affected. This is a network-accessible vulnerability requiring no authentication, making it a significant availability risk for organizations relying on these firewalls for critical security functions.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-754
Affected products
192 configuration(s)
Published / Modified
2026-07-09 / 2026-08-11

NVD description (verbatim)

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-0287 encompasses multiple DoS flaws in Palo Alto Networks PAN-OS that stem from improper error handling (CWE-754). An unauthenticated attacker with network access can send malformed traffic destined for or transiting through a dataplane interface to trigger a crash condition. Successive exploitation attempts induce the device to enter maintenance mode, effectively disabling forwarding operations. The vulnerability requires no special privileges or user interaction and succeeds across network boundaries, earning a CVSS 3.1 score of 7.5 (HIGH). Cloud NGFW and multiple PAN-OS versions spanning the product line are impacted; Panorama deployments remain unaffected.

Business impact

For organizations operating Palo Alto firewalls as perimeter or internal security controls, this vulnerability poses a direct threat to network availability. Repeated attacks can render the firewall unavailable, disrupting all east-west or north-south traffic depending on deployment architecture. Financial impact includes potential service downtime, incident response costs, and reputational harm from security control failures. Organizations with single firewalls or limited redundancy face heightened risk of extended outages. The lack of authentication or complexity requirements means an attacker does not need prior compromise or sophisticated reconnaissance.

Affected systems

Palo Alto Networks PAN-OS across multiple versions and Cloud NGFW deployments are in scope. Panorama management appliances are explicitly not vulnerable. Determine your specific PAN-OS version and Cloud NGFW footprint and cross-reference against the vendor security advisory to confirm which of your instances fall within vulnerable ranges. The breadth of affected versions suggests long-standing code patterns rather than a recent regression.

Exploitability

This vulnerability has a low barrier to exploitation. It requires only network reachability to a dataplane interface and does not demand authentication, valid sessions, or user interaction. The attacker simply crafts and transmits network packets; no special tools or zero-day code are necessary once the attack pattern is understood. However, exploitation is not currently tracked in public exploit databases or KEV catalogs, suggesting either limited real-world disclosure or early-stage awareness. Organizations should assume exploitation is feasible and prioritize patching accordingly.

Remediation

Apply security updates from Palo Alto Networks that address these DoS flaws. Consult the official Palo Alto security advisory for specific patch versions applicable to your PAN-OS and Cloud NGFW deployments. In the interim, implement network access controls to restrict untrusted sources from reaching dataplane interfaces where feasible. Consider deploying firewalls in redundant active-active or active-passive configurations to maintain availability if one device is compromised. Monitor firewall logs and system health metrics for unexpected restarts or maintenance mode transitions.

Patch guidance

Contact Palo Alto Networks or consult their official security bulletin to obtain patch versions addressing CVE-2026-0287 for your specific PAN-OS and Cloud NGFW versions. Patches should be validated in a staging environment before production deployment, given the criticality of firewall availability. Plan patching windows during scheduled maintenance to minimize service disruption. If your organization uses PAN-OS in highly redundant configurations, coordinate patching across nodes to maintain protection during the update cycle.

Detection guidance

Monitor firewall system logs for unexpected device restarts, transitions to maintenance mode, or crashes without user-initiated actions. Collect netflow or packet capture data on dataplane interfaces for anomalous traffic patterns preceding outages. Configure alerting on PAN-OS health checks and CPU/memory anomalies that may signal exploitation attempts. Correlate firewall downtime with external attack activity or suspicious network traffic originating from unexpected sources. Security information and event management (SIEM) integration can automate detection of repeated DoS attempts.

Why prioritize this

This vulnerability merits urgent prioritization because it directly threatens the availability of a critical security control with low exploitation complexity and no authentication barrier. A determined attacker can repeatedly render the firewall inoperable, causing cascading failures in dependent network services. The impact moves beyond confidentiality or integrity concerns into operational resilience—a foundational business requirement. Immediate patching or compensating controls should precede other remediation efforts, especially in environments where the affected firewall serves as a single point of entry or exit.

Risk score, explained

The CVSS 3.1 score of 7.5 (HIGH) reflects the convergence of high exploitability (AV:N, AC:L, PR:N, UI:N) and severe availability impact (A:H). No confidentiality or integrity loss occurs, limiting the score from CRITICAL. However, the network-accessible, unauthenticated nature and guaranteed denial of service effect justify the HIGH severity band. In operational terms, availability of security infrastructure is a business-critical metric, warranting internal risk elevation beyond the base CVSS score.

Frequently asked questions

Can Panorama deployments be exploited via this vulnerability?

No. Palo Alto Networks has confirmed that Panorama management appliances are not affected by CVE-2026-0287. Only PAN-OS firewalls and Cloud NGFW instances are vulnerable. However, if your Panorama instance manages vulnerable PAN-OS devices, you should still prioritize patching the firewalls themselves to restore their availability and correct functionality.

Does this vulnerability require the attacker to be inside my network or can it be exploited from the Internet?

The vulnerability is exploitable from any network location that can reach a dataplane interface on the PAN-OS device. If your firewall's management or dataplane interfaces are Internet-facing or reachable from untrusted networks, the attack surface is maximized. Conversely, if dataplane interfaces are only accessible from trusted internal networks, the practical exploitation risk is lower—though still significant.

What should I do if patching my firewalls immediately is not feasible?

Implement network segmentation to restrict which sources can send traffic to dataplane interfaces. Deploy firewalls in redundant pairs configured for failover, so that a successful DoS attack on one device does not cause complete network outage. Monitor system logs and health metrics closely for signs of exploitation. Increase your incident response readiness so that if an attack occurs, your team can quickly reboot the firewall or fail over to a backup. Continue planning for patch deployment as a priority once testing is complete.

Is there an exploit in the public domain for this vulnerability?

CVE-2026-0287 is not yet listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploit code is widely documented. This does not mean the vulnerability is unexploitable or safe to ignore—it reflects either limited public disclosure or early awareness post-publication. Organizations should assume that attack code will emerge and prioritize patching accordingly.

This analysis is for informational purposes and reflects threat intelligence as of the publication date. Patch versions, affected product ranges, and remediation steps must be verified against official Palo Alto Networks security advisories and your organization's system inventory. SEC.co does not provide exploit code or weaponization guidance. Organizations should conduct independent risk assessments and testing before applying patches to production environments. Consult your vendor and internal security teams for guidance tailored to your specific infrastructure. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).