Back

MEDIUM

PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

Published Jun 10, 2026

Description

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Affected products

Remediation

Vendor solution

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h5 or 12.1.5 or later. PAN-OS 11.2 11.2.8 through 11.2.9 Upgrade to 11.2.10 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h4 or 11.2.10 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h17 or 11.2.10 or later. PAN-OS 11.1 11.1.11 or later Upgrade to 11.1.12 or later.   11.1.7 through 11.1.10-h* Upgrade to 11.1.10-h7 or 11.1.12 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h21 or 11.1.12 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h33 or 11.1.12 or later. PAN-OS 10.2 10.2.17 or later Upgrade to 10.2.18 or later.   10.2.4 through 10.2.16-h* Upgrade to 10.2.16-h6 or 10.2.18 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h21 or 10.2.18 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h36 or 10.2.18 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h34 or 10.2.18 or later. All older   Upgrade to a supported fixed version. unsupported PAN-OS versions Panorama   No action needed. Prisma Access No action needed.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Jun 10, 2026
Updated Jul 14, 2026
Reserved Nov 3, 2025
CISA Vulnrichment
Updated Jun 11, 2026
NVD
Status Modified
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a