Palo Alto Networks has fixed a critical denial of service (DoS) vulnerability in its PAN-OS firewall, which is documented as CVE-2026-0227 , and allows unauthenticated attackers to disrupt the operation of GlobalProtect gateways and portals.
See also: New attacks target Palo Alto Networks' GlobalProtect portals

The vulnerability is rated with a CVSS v4.0 score of 7.7 (high severity) and is due to insufficient control of unusual or exceptional conditions, resulting in firewalls entering maintenance mode after repeated exploitation attempts.
The issue was published on January 14, 2026 and affects multiple versions of PAN-OS, but does not affect Cloud NGFW. The exploitation is performed remotely over the network, with low complexity, without the need for privileges or user interaction, which makes it easily automated.
See also: Palo Alto Networks acquires Chronosphere for 3.35 billion

The vulnerability is related to CWE-754 (Improper checking of unusual conditions) and CAPEC-210 (Abuse of existing functionality) and seriously affects the availability of systems, without affecting the confidentiality or integrity of data.
Palo Alto says a proof-of-concept exploit, but no active exploits have been identified. The vulnerability only exists when GlobalProtect gateways or portals are enabled on NGFWs running PAN-OS or in Prisma Access environments, which are widely used for remote access.
The vulnerability affects both older and newer branches of PAN-OS. There are no available mitigations and an immediate upgrade to patched versions, such as PAN-OS 12.1.4 or 11.2.10-h2. Recovery requires moderate effort and administrator intervention.
See also: Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

The discovery is attributed to an external researcher, while community discussions point to recent scanning activity that may target this vulnerability. Organizations are advised to check their configurations via Palo Alto's support portal and monitor for potential DoS attacks while the POC remains available.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
