Security.Paloaltonetworks Critical Buffer Overflow Vulnerabilities in PAN-OS Affecting Firewalls
Article Content
- •CVE-2026-0264 allows DoS or arbitrary code execution on PA-Series hardware.
- •CVE-2026-0263 enables remote code execution via IKEv2 processing.
- •Both vulnerabilities are not exploitable on Panorama, Cloud NGFW, or Prisma Access.
Palo Alto Networks disclosed two critical buffer overflow vulnerabilities in PAN-OS on May 13, 2026. CVE-2026-0264 allows unauthenticated attackers to cause a denial of service or execute arbitrary code on PA-Series hardware. CVE-2026-0263 also enables remote code execution with elevated privileges via IKEv2 processing. Both vulnerabilities require specific configurations to be exploitable, including enabled DNS Proxy or IKEv2 VPN tunnels with Post Quantum Cryptography. The risk is highest for PA-Series hardware, while Panorama, Cloud NGFW, and Prisma Access are unaffected. Palo Alto Networks has not reported any known exploitation of these vulnerabilities. Users are advised to upgrade to the latest PAN-OS versions to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-0263 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…