Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS - CVE-2026-0287

 

Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS - CVE-2026-0287

Published: July 10, 2026


Vulnerability identifier: #VU137318
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0287
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper check for unusual or exceptional conditions in network traffic processing on the dataplane interface when processing specially crafted network traffic sent to or through a dataplane interface. A remote attacker can send specially crafted network traffic to cause a denial of service.

Repeated attempts to trigger the issue result in the firewall entering maintenance mode. Panorama is not impacted.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2026-0287

Install security update from vendor's website.

Palo Alto PAN-OS - addressed in versions 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8, 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16, 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13, 12.1.4-h8, 12.1.7-h2, 12.1.8

External References

Related Security Bulletins