CVE-2026-0269
MEDIUMPAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
Title source: cnaDescription
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
References (2)
Core 2
Core References
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-967325.html
Vendor Advisory vendor-advisory
https://security.paloaltonetworks.com/CVE-2026-0269
Scores
CVSS v3
5.7
EPSS
0.0022
EPSS Percentile
13.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-754
Status
published
Products (9)
Palo Alto Networks/Cloud NGFW
All
Palo Alto Networks/PAN-OS
10.2.0 - 10.2.16-h6
Palo Alto Networks/PAN-OS
11.1.0 - 11.1.6-h21
Palo Alto Networks/PAN-OS
11.2.0 - 11.2.10
Palo Alto Networks/PAN-OS
12.1.0 - 12.1.5
Palo Alto Networks/Panorama
All
Palo Alto Networks/Prisma Access
All
paloaltonetworks/pan-os
10.2.7 (28 CPE variants)
paloaltonetworks/pan-os
10.2.10 (15 CPE variants)
Published
Jun 10, 2026
Tracked Since
Jun 11, 2026