CVE-2026-0264: Palo Alto Networks PAN-OS

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only). Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Affected products

  • Palo Alto Networks PAN-OS: before 10.2.7 (fixed in 10.2.7); from 10.2.8, before 10.2.10 (fixed in 10.2.10); from 10.2.11, before 10.2.13 (fixed in 10.2.13); from 10.2.14, before 10.2.16 (fixed in 10.2.16); version 10.2.7 only; version 10.2.10 only; …
  • Siemens Ruggedcom APE1808 Firmware: affected versions not specified

Published 2026-05-13. Last modified 2026-07-14.