VDB

CVE-2026-0280

CVE-2026-0280 PUBLISHED CVSS 1.7 LOW

Reported by palo_alto · Published July 9, 2026

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

Risk Scores

CVSS 4.0
1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/AU:Y/V:D/RE:M/U:Amber

Affected Products

VendorProductVersions
Palo Alto NetworksCloud NGFWAll
Palo Alto NetworksPAN-OS12.1.0, 11.2.0, 11.1.0
Palo Alto NetworksPanoramaAll
Palo Alto NetworksPrisma Access11.2.0, 10.2.0
Palo Alto NetworksPrisma Access11.2.0, 10.2.0
Palo Alto NetworksCloud NGFWAll
palo_alto_networksprisma_access11.2.7, 10.2.10
Palo Alto NetworksPAN-OS12.1.0, 11.2.0, 11.1.0
Palo Alto NetworksPanoramaAll
palo_alto_networkspan-os11.1.7, 11.1.6, 11.1.4

Timeline

  • Jul 9, 2026 CVE Published
  • Jul 9, 2026 CVE Updated
  • Jul 11, 2026 Coalition ESS Score

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›