An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OSĀ® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0280 | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-104023.html |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2026-07-09 19:16
Updated : 2026-08-11 13:17
NVD link : CVE-2026-0280
Mitre link : CVE-2026-0280
CVE.ORG link : CVE-2026-0280
JSON object : View
Products Affected
paloaltonetworks
- pan-os
CWE
CWE-131
Incorrect Calculation of Buffer Size
