VDB
CVE-2026-0287
CVE-2026-0287
PUBLISHED
CVSS 6.6 MEDIUM
Reported by palo_alto · Published July 9, 2026
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.
Risk Scores
CVSS 4.0
6.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palo Alto Networks | Cloud NGFW | All |
| Palo Alto Networks | PAN-OS | 12.1.0, 11.2.0, 11.1.0 |
| Palo Alto Networks | Prisma Access | 11.2.0, 10.2.0 |
| Palo Alto Networks | Prisma Access | 11.2.0, 10.2.0 |
| palo_alto_networks | prisma_access | 10.2.10, 11.2.7 |
| Palo Alto Networks | PAN-OS | 11.2.0, 11.1.0, 10.2.0 |
| Palo Alto Networks | Cloud NGFW | All |
| palo_alto_networks | pan-os | 11.1.7, 11.1.10, 11.1.13 |
| palo_alto_networks | cloud_ngfw | all, all |
Timeline
- Jul 9, 2026 CVE Published
- Jul 9, 2026 CVE Updated
- Jul 11, 2026 Coalition ESS Score
References
- https://security.paloaltonetworks.com/CVE-2026-PAN-323400 vendor-advisory