Skip to content
Critical Buffer Overflow Vulnerabilities in PAN-OS Affecting Firewalls

Critical Buffer Overflow Vulnerabilities in PAN-OS Affecting Firewalls

First seen 13 May 2026, 20:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •May 14, 2026 at 19:46 UTC

Palo Alto Networks disclosed two critical buffer overflow vulnerabilities in PAN-OS on May 13, 2026. CVE-2026-0264 allows unauthenticated attackers to cause a denial of service or execute arbitrary code on PA-Series hardware. CVE-2026-0263 also enables remote code execution with elevated privileges via IKEv2 processing. Both vulnerabilities require specific configurations to be exploitable, including enabled DNS Proxy or IKEv2 VPN tunnels with Post Quantum Cryptography. The risk is highest for PA-Series hardware, while Panorama, Cloud NGFW, and Prisma Access are unaffected. Palo Alto Networks has not reported any known exploitation of these vulnerabilities. Users are advised to upgrade to the latest PAN-OS versions to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 146d ago How this analysis works

Timeline

2026-05-13
CVE-2026-0264 published
A buffer overflow in PAN-OS allows DoS and potential arbitrary code execution on PA-Series hardware.
Security.Paloaltonetworks
2026-05-13
CVE-2026-0263 published
A buffer overflow in IKEv2 processing enables remote code execution with elevated privileges on PAN-OS.
Security.Paloaltonetworks

More articles in this cluster (5)

Following this threat?

Track CVE-2026-0263 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed