CVE-2026-0243

Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through IPv6 Crafted Packet

Severity
Medium 4.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.0th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto

Description

A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.

Weakness: CWE-606

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma SD-WAN SASE / SSE / Secure Web cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Prisma SD-WAN ION

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution Prisma SD-WAN ION 6.5 6.5.1 through 6.5.3 Upgrade to 6.5.3-b15 or later. Prisma SD-WAN ION 6.4 6.4.1 through 6.4.3 Upgrade to 6.4.3-b8 or later. Prisma SD-WAN ION 6.3 6.3.1 through 6.3.6 Upgrade to 6.3.6-b10 or later. Prisma SD-WAN ION 6.1 No action needed. Prisma SD-WAN ION 5.6 No action needed.

Something wrong here?