CVE-2026-0280: PAN-OS: IPv6 Firewall Policy Bypass (Severity: LOW)
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.8Fixed in 12.1.7-h2Fixed in 12.1.4-h8Fixed in 11.2.13Fixed in 11.2.10-h11Fixed in 11.2.7-h18Fixed in 11.2.4-h20Fixed in 11.1.16Fixed in 11.1.13-h9Fixed in 11.1.10-h30Fixed in 11.1.7-h8Fixed in 11.1.6-h35Fixed in 11.1.4-h35Fixed in 10.2.18-h8Fixed in 10.2.16-h9Fixed in 10.2.13-h23Fixed in 10.2.10-h39Fixed in 10.2.7-h36 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2.7-h18Fixed in 10.2.10-h39 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.7-h36 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h23 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.16-h9 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h39 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h35 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.13-h9 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.6-h35 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.7-h8 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.10-h30 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h20 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.7-h18 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.10-h11 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.4-h8 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18-h8 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.16 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.13 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.7-h2 - Upgrade
Upgrade
Prisma Accessto a version that resolves this vulnerability.Fixed in 10.2.10-h39 - Upgrade
Upgrade
Prisma Accessto a version that resolves this vulnerability.Fixed in 11.2.7-h18 - Configuration
Enable the default "Non SYN TCP Reject" setting via: set deviceconfig setting session tcp-reject-non-syn yes
PAN-OS deviceconfig (default Non SYN TCP Reject setting) session tcp-reject-non-syn = yes
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0280?
CVE-2026-0280 has a medium severity rating of 6.3.
How do I fix CVE-2026-0280?
To fix CVE-2026-0280, ensure that you update your Palo Alto Networks PAN-OS software to the latest version.
What are the potential impacts of CVE-2026-0280?
CVE-2026-0280 allows an unauthenticated attacker to bypass firewall policies and access protected services.
Which products are affected by CVE-2026-0280?
CVE-2026-0280 affects Palo Alto Networks PAN-OS but not Cloud NGFW or Panorama.
Can CVE-2026-0280 be exploited remotely?
Yes, CVE-2026-0280 can be exploited remotely, as it allows unauthorized access to services through IPv6 packets.