CVE-2026-0229
PAN-OS: Denial of Service in Advanced DNS Security Feature
Description
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Weakness: CWE-754
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
Credit
an internal reporter, jliu@TikkalaSecurity,
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All No action needed. PAN-OS 12.1 12.1.2 through 12.1.3 Upgrade to 12.1.4 or later. PAN-OS 11.2 11.2.0 through 11.2.9 Upgrade to 11.2.10 or later. PAN-OS 11.1 No action needed. PAN-OS 10.2 No action needed. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access All No action needed.