CVE-2026-0229: Palo Alto Networks Cloud Ngfw
Medium severity, CVSS 6.6. EPSS: 0.6% chance of exploitation in the next 30 days.
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Affected products
- Palo Alto Networks Cloud Ngfw
- Palo Alto Networks PAN-OS: from 12.1.0, before 12.1.4 (fixed in 12.1.4); from 11.2.0, before 11.2.10 (fixed in 11.2.10)
- Palo Alto Networks Prisma Access
Published 2026-02-11. Last modified 2026-06-17.