CVE-2026-0269 Details
Description
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
A memory corruption vulnerability has been identified in Palo Alto Networks PAN-OS software, specifically in the processing of tunnel traffic. This vulnerability allows an authenticated user to send a maliciously crafted packet that initiates a system reboot. Repeated attempts to reboot the system cause the firewall to enter maintenance mode. This issue does not affect Panorama, Cloud NGFW, or Prisma Access.
Users can upgrade to PAN-OS versions 12.1.4-h5, 12.1.5, 11.2.10, 11.1.12, or 10.2.18. For older unsupported PAN-OS versions, upgrading to a supported fixed version is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-967325.html | siemens-SADP | |
| https://security.paloaltonetworks.com/CVE-2026-0269 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks pan-os | >= 10.2.0, < 10.2.7 >= 10.2.8, < 10.2.10 >= 10.2.11, < 10.2.13 >= 10.2.14, < 10.2.16 10.2.7 - 10.2.7 h1 10.2.7 h10 10.2.7 h11 10.2.7 h12 10.2.7 h13 10.2.7 h14 10.2.7 h15 10.2.7 h16 10.2.7 h17 10.2.7 h18 10.2.7 h19 10.2.7 h2 10.2.7 h20 10.2.7 h21 10.2.7 h22 10.2.7 h23 10.2.7 h24 10.2.7 h3 10.2.7 h32 10.2.7 h34 10.2.7 h35 10.2.7 h4 10.2.7 h5 10.2.7 h6 10.2.7 h7 10.2.7 h8 10.2.7 h9 10.2.10 - 10.2.10 h1 10.2.10 h10 10.2.10 h11 10.2.10 h12 10.2.10 h13 10.2.10 h14 10.2.10 h17 10.2.10 h18 10.2.10 h2 10.2.10 h21 10.2.10 h27 10.2.10 h3 10.2.10 h30 10.2.10 h31 10.2.10 h4 10.2.10 h5 10.2.10 h6 10.2.10 h7 10.2.13 - 10.2.13 h1 10.2.13 h10 10.2.13 h15 10.2.13 h16 10.2.13 h18 10.2.13 h2 10.2.13 h3 10.2.13 h4 10.2.13 h5 10.2.13 h7 10.2.16 - 10.2.16 h1 10.2.16 h4 10.2.17 >= 11.1.0, < 11.1.4 >= 11.1.5, < 11.1.6 >= 11.1.7, < 11.1.10 11.1.4 - 11.1.4 h1 11.1.4 h10 11.1.4 h11 11.1.4 h12 11.1.4 h13 11.1.4 h15 11.1.4 h17 11.1.4 h18 11.1.4 h2 11.1.4 h25 11.1.4 h27 11.1.4 h3 11.1.4 h32 11.1.4 h4 11.1.4 h5 11.1.4 h6 11.1.4 h7 11.1.4 h8 11.1.4 h9 11.1.6 - 11.1.6 h1 11.1.6 h10 11.1.6 h14 11.1.6 h17 11.1.6 h18 11.1.6 h19 11.1.6 h2 11.1.6 h20 11.1.6 h3 11.1.6 h4 11.1.6 h6 11.1.6 h7 11.1.10 - 11.1.10 h1 11.1.10 h4 11.1.10 h5 11.1.11 - >= 11.2.0, < 11.2.4 >= 11.2.5, < 11.2.7 >= 11.2.8, < 11.2.10 11.2.4 - 11.2.4 h1 11.2.4 h10 11.2.4 h11 11.2.4 h12 11.2.4 h14 11.2.4 h15 11.2.4 h17 11.2.4 h2 11.2.4 h3 11.2.4 h4 11.2.4 h5 11.2.4 h6 11.2.4 h7 11.2.4 h8 11.2.4 h9 11.2.7 - 11.2.7 h1 11.2.7 h2 11.2.7 h3 >= 12.1.0, < 12.1.4 12.1.4 - 12.1.4 h2 12.1.4 h3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | siemens-SADP |
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | [email protected] |