CVE-2026-0229

PAN-OS: Denial of Service in Advanced DNS Security Feature

Severity
Medium 6.6
CVSS 4.0
Exploited
Not listed
EPSS
0.005
44.0th percentile
Discovered by
Vendor
Vendor-published field
Published
Feb 11, 2026
Assigned by palo_alto

Description

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Weakness: CWE-754

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

an internal reporter, jliu@TikkalaSecurity,

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All   No action needed.  PAN-OS 12.1 12.1.2 through 12.1.3 Upgrade to 12.1.4 or later. PAN-OS 11.2 11.2.0 through 11.2.9 Upgrade to 11.2.10 or later. PAN-OS 11.1 No action needed. PAN-OS 10.2 No action needed. All older   Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access All No action needed.

Something wrong here?