CVE-2026-0243: Palo Alto Networks Prisma SD-WAN

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.

Affected products

  • Palo Alto Networks Prisma SD-WAN: from 6.3.1, before 6.3.6 (fixed in 6.3.6); from 6.4.1, before 6.4.3 (fixed in 6.4.3); from 6.5.1, before 6.5.3 (fixed in 6.5.3); version 6.3.6 only; version 6.4.3 only; version 6.5.3 only

Published 2026-05-13. Last modified 2026-07-14.