Heap-based buffer overflow in Palo Alto PAN-OS - CVE-2026-0264
Published: May 19, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the DNS proxy and DNS server features when processing specially crafted network traffic. A remote attacker can send specially crafted network traffic to execute arbitrary code.
This impact applies to PA-Series hardware only.