Out-of-bounds write in Palo Alto PAN-OS - CVE-2026-0263
Published: May 19, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in IKEv2 processing when processing IKEv2 traffic. A remote attacker can send specially crafted IKEv2 packets to execute arbitrary code.
Exploitation requires IKEv2 VPN tunnels configured with Post Quantum Cryptography (PQC).