Palo Alto Networks Addresses High-Severity DoS Vulnerability in Firewalls
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Palo Alto Networks has recently addressed a critical vulnerability, identified as CVE-2026-0227, which could enable unauthorized attackers to disable firewall protections via denial-of-service (DoS) attacks. This security flaw impacts next-generation firewalls operating on PAN-OS 10.1 or later, as well as Prisma Access configurations when the GlobalProtect gateway or portal is activated. The company has confirmed that most cloud-based Prisma Access instances have already been patched, while remaining instances are scheduled for upgrades.
The vulnerability allows an unauthenticated attacker to force the firewall into maintenance mode through repeated attempts to exploit the flaw. As of now, there is no evidence that this vulnerability is being actively exploited in the wild, but the potential for such attacks remains a significant concern.
Internet security organization Shadowserver has reported tracking nearly 6,000 Palo Alto Networks firewalls exposed online, although it is unclear how many of these have vulnerable configurations or have already been patched. This situation highlights the ongoing risks associated with unpatched vulnerabilities in widely used security products.
Palo Alto Networks has released security updates for all affected versions, advising administrators to upgrade to the latest releases to mitigate risks. Specific upgrade recommendations include:
- PAN-OS 12.1: Upgrade to 12.1.4 or later.
- PAN-OS 11.2: Upgrade to 11.2.10-h2 or later.
- PAN-OS 11.1: Upgrade to 11.1.13 or later.
- PAN-OS 10.2: Upgrade to 10.2.18-h1 or later.
- Prisma Access 11.2: Upgrade to 11.2.7-h8 or later.
- Prisma Access 10.2: Upgrade to 10.2.10-h29 or later.
Given the history of attacks targeting Palo Alto Networks products, including previously patched zero-day vulnerabilities, organizations using these firewalls should remain vigilant. In November 2024, the company patched two zero-day vulnerabilities that allowed attackers to gain root privileges, leading to the compromise of thousands of firewalls.
As cyber threats evolve, the importance of timely updates and security patches cannot be overstated. Organizations should prioritize monitoring their firewall configurations and ensuring that they are running the latest software versions to protect against potential exploits.
Key Takeaways
- Check if your Palo Alto Networks firewall is running PAN-OS 10.1 or later and apply the latest security updates.
- Review your Prisma Access configurations to ensure the GlobalProtect gateway is secured.
- Monitor your firewall for any unusual activity that may indicate attempts to exploit vulnerabilities.
- Stay informed about new vulnerabilities and patches released by Palo Alto Networks.
- Consider conducting a security audit to assess the overall health of your network defenses.
Key Terms & Concepts
- CVE-2026-0227: In this article, CVE-2026-0227 refers to a high-severity vulnerability in Palo Alto Networks firewalls that allows denial-of-service attacks.
- PAN-OS: PAN-OS is the operating system used by Palo Alto Networks’ next-generation firewalls.
- GlobalProtect: GlobalProtect is the VPN and remote access component of Palo Alto Networks’ PAN-OS firewalls.
- denial-of-service (DoS): A denial-of-service (DoS) attack aims to make a service unavailable to its intended users by overwhelming it with traffic.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.