CVE-2026-0229: PAN-OS: Denial of Service in Advanced DNS Security Feature
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.
Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Other sources
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.
Panorama, Cloud NGFW, and Prisma Access® are not impacted by this vulnerability.
— Palo Alto Networks
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0229?
The severity of CVE-2026-0229 is classified as MEDIUM.
How do I fix CVE-2026-0229?
To mitigate CVE-2026-0229, upgrade to a patched version of PAN-OS that addresses the vulnerability.
What products are affected by CVE-2026-0229?
CVE-2026-0229 affects Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access.
What type of vulnerability is CVE-2026-0229?
CVE-2026-0229 is a denial-of-service (DoS) vulnerability.
Can an authenticated user exploit CVE-2026-0229?
No, CVE-2026-0229 can be exploited by unauthenticated attackers.