CVE-2026-0287: Palo Alto Networks Cloud Ngfw

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.

Affected products

  • Palo Alto Networks Cloud Ngfw: any version
  • Palo Alto Networks PAN-OS: from 10.2.0, before 10.2.7 (fixed in 10.2.7); from 10.2.8, before 10.2.10 (fixed in 10.2.10); from 10.2.11, before 10.2.13 (fixed in 10.2.13); from 10.2.14, before 10.2.16 (fixed in 10.2.16); version 10.2.7 only; version 10.2.10 only; …

Published 2026-07-09. Last modified 2026-08-11.