HomeSecurityVulnerability in Palo Alto Networks firewall allows DoS attacks

Vulnerability in Palo Alto Networks firewall allows DoS attacks

Palo Alto Networks has fixed a critical denial of service (DoS) vulnerability in its PAN-OS firewall, which is documented as CVE-2026-0227 , and allows unauthenticated attackers to disrupt the operation of GlobalProtect gateways and portals.

See also: New attacks target Palo Alto Networks' GlobalProtect portals

Palo Alto Networks

The vulnerability is rated with a CVSS v4.0 score of 7.7 (high severity) and is due to insufficient control of unusual or exceptional conditions, resulting in firewalls entering maintenance mode after repeated exploitation attempts.

The issue was published on January 14, 2026 and affects multiple versions of PAN-OS, but does not affect Cloud NGFW. The exploitation is performed remotely over the network, with low complexity, without the need for privileges or user interaction, which makes it easily automated.

See also: Palo Alto Networks acquires Chronosphere for 3.35 billion

Vulnerability in Palo Alto Networks firewall allows DoS attacks

The vulnerability is related to CWE-754 (Improper checking of unusual conditions) and CAPEC-210 (Abuse of existing functionality) and seriously affects the availability of systems, without affecting the confidentiality or integrity of data.

Palo Alto says a proof-of-concept exploit, but no active exploits have been identified. The vulnerability only exists when GlobalProtect gateways or portals are enabled on NGFWs running PAN-OS or in Prisma Access environments, which are widely used for remote access.

The vulnerability affects both older and newer branches of PAN-OS. There are no available mitigations and an immediate upgrade to patched versions, such as PAN-OS 12.1.4 or 11.2.10-h2. Recovery requires moderate effort and administrator intervention.

See also: Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Vulnerability in Palo Alto Networks firewall allows DoS attacks

The discovery is attributed to an external researcher, while community discussions point to recent scanning activity that may target this vulnerability. Organizations are advised to check their configurations via Palo Alto's support portal and monitor for potential DoS attacks while the POC remains available.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS