Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS - CVE-2026-0269

 

Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS - CVE-2026-0269

Published: June 16, 2026


Vulnerability identifier: #VU134593
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0269
CWE-ID: CWE-754
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to memory corruption in tunnel traffic processing when handling maliciously crafted tunnel packets. A remote user can send a maliciously crafted packet to cause a denial of service.

Repeated exploitation attempts can cause the firewall to enter maintenance mode. The issue affects firewalls configured with IPSec tunnels or GlobalProtect gateways for remote access.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2026-0269

Install security update from vendor's website.

Palo Alto PAN-OS - addressed in versions 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h6, 10.2.18, 11.1.4-h33, 11.1.6-h21, 11.1.10-h7, 11.1.12, 11.2.4-h17, 11.2.7-h4, 11.2.10, 12.1.4-h5, 12.1.5

External References

Related Security Bulletins