Vulnerability identifier: #VU137309
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0280
CWE-ID: CWE-131
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass firewall security policy enforcement.
The vulnerability exists due to incorrect calculation of buffer size in the dataplane when processing IPv6 packets. A remote attacker can send crafted network traffic to bypass firewall security policy enforcement.
Only firewalls with IPv6 enabled on one or more interfaces are vulnerable. Cloud NGFW and Panorama are not impacted by this vulnerability.
Affected software
Palo Alto PAN-OS
How to mitigate CVE-2026-0280
Install security update from vendor's website.
Palo Alto PAN-OS - addressed in versions 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8, 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16, 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, 11.2.13, 12.1.4-h8, 12.1.7-h2, 12.1.8
External References
Related Security Bulletins