CVE-2026-0263: PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7Fixed in 12.1.4-h5Fixed in 11.2.12Fixed in 11.2.10-h6Fixed in 11.2.7-h13Fixed in 11.2.4-h17Fixed in 11.1.15Fixed in 11.1.13-h5Fixed in 11.1.10-h25Fixed in 11.1.7-h6Fixed in 11.1.6-h32Fixed in 11.1.4-h33 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 11.1to a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 11.2to a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Palo Alto Networks PAN-OS 12.1to a version that resolves this vulnerability.Fixed in 12.1.7 - Compensating control
For customers using IKEv2 VPN, mitigate by configuring IKEv2 VPN tunnels only with NIST approved Post Quantum Cryptography (PQC) ciphers.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0263?
CVE-2026-0263 has a severity rating of HIGH due to its potential for remote code execution.
What systems are affected by CVE-2026-0263?
CVE-2026-0263 affects the Palo Alto Networks PAN-OS software.
How do I fix CVE-2026-0263?
To fix CVE-2026-0263, update to the latest version of Palo Alto Networks PAN-OS that addresses this vulnerability.
What type of vulnerability is CVE-2026-0263?
CVE-2026-0263 is a buffer overflow vulnerability that allows for remote code execution.
What can attackers do with CVE-2026-0263?
Attackers exploiting CVE-2026-0263 can execute arbitrary code with elevated privileges on the affected firewall.