Attackers can force Palo Alto firewalls into maintenance mode
Under certain conditions, attackers can exploit a vulnerability in PAN-OS and thus attack Palo Alto Networks firewalls. So far, according to the IT security company, there are no indications of attacks.
If attackers successfully exploit the DoS vulnerability (CVE-2026-0227 “ high ”), they can put devices into maintenance mode. In this state, it can be assumed that the firewall protection is bypassed. In a post, the developers explain that only PAN-OS NGFW and Prisma Access configurations with GlobalProtect gateway/portal enabled are vulnerable.
Cloud NGFW is reportedly already secured against the described attack. The following security patches have been released for PAN-OS:
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
