Incorrect Calculation of Buffer Size in Palo Alto PAN-OS - CVE-2026-0280

 

Incorrect Calculation of Buffer Size in Palo Alto PAN-OS - CVE-2026-0280

Published: July 10, 2026


Vulnerability identifier: #VU137309
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0280
CWE-ID: CWE-131
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass firewall security policy enforcement.

The vulnerability exists due to incorrect calculation of buffer size in the dataplane when processing IPv6 packets. A remote attacker can send crafted network traffic to bypass firewall security policy enforcement.

Only firewalls with IPv6 enabled on one or more interfaces are vulnerable. Cloud NGFW and Panorama are not impacted by this vulnerability.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2026-0280

Install security update from vendor's website.

Palo Alto PAN-OS - addressed in versions 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8, 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16, 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, 11.2.13, 12.1.4-h8, 12.1.7-h2, 12.1.8

External References

Related Security Bulletins