CVE-2026-0263: Palo Alto Networks PAN-OS
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.
Affected products
- Palo Alto Networks PAN-OS: from 11.1.0, before 11.1.4 (fixed in 11.1.4); from 11.1.5, before 11.1.6 (fixed in 11.1.6); from 11.1.8, before 11.1.10 (fixed in 11.1.10); from 11.1.11, before 11.1.13 (fixed in 11.1.13); version 11.1.4 only; version 11.1.6 only; …
Published 2026-05-13. Last modified 2026-07-14.