Skip to content
All vulnerabilities
CVE-2026-0264

PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

Severity
Critical9.8CVSS 3.1, Critical
Known exploited
Not listed
Exploit prediction
0.47%
Published
13 May 2026Updated 14 Jul 2026 · Last verified 28 Sept 2026

Known remediation

Fixed releases per branch, as the vendor states them. Patcharo never infers a fix.

  • Palo Alto Networks PAN-OS

    Vendor advisory
    • 12.112.1.4-h5, 12.1.7
    • 11.211.2.4-h17, 11.2.7-h13, 11.2.10-h6, 11.2.12
    • 11.111.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15
    • 10.210.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6

Workaround / Vendor remediation

Workaround · PAN-OS

Customers can mitigate the risk of this issue by taking either of the following actions: Action 1: * Disassociate DNS Proxy from externally accessible interfaces in order to reduce your attack surface; AND * Configure DNS server with a RFC1918 or a public trusted IP address. OR Action 2: * Disable the DNS Proxy feature (Network > DNS Proxy) if it is not being used; AND * Configure DNS server with a RFC1918 or a public trusted IP address. Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510027 from Applications and Threats content version 9100-10044 and later.

Vendor remediation · PAN-OS

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed PAN-OS 12.1 12.1.5 through 12.1.6 Upgrade to 12.1.7 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h5 or 12.1.7 or later. PAN-OS 11.2 11.2.11 or later Upgrade to 11.2.12 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h6 or 11.2.12 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h13 or 11.2.10 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h17 or 11.2.7 or later. PAN-OS 11.1 11.1.14 or later Upgrade to 11.1.15 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h5 or 11.1.15 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h25 or 11.1.15 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h6 or 11.1.15 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h32 or 11.1.15 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h33 or 11.1.15 or later. PAN-OS 10.2 10.2.17 through 10.2.18-h* …

Description

Title, description and vendor guidance are quoted from the source records.

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only). Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Weakness: CWE-122

Known exploited

Not listed in CISA KEV as of the last check.

Exploit prediction

0.47% probability of exploitation in the next 30 days (percentile 39%).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the source states, per branch

Versions matched by Patcharo

Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)

BranchAffectedFixed in
12.1
>= 12.1.0, < 12.1.4-h5
>= 12.1.5, < 12.1.7
12.1.4-h5
12.1.7
11.2
>= 11.2.0, < 11.2.4-h17
>= 11.2.5, < 11.2.7-h13
>= 11.2.8, < 11.2.10-h6
>= 11.2.11, < 11.2.12
11.2.4-h17
11.2.7-h13
11.2.10-h6
11.2.12
11.1
>= 11.1.0, < 11.1.4-h33
>= 11.1.5, < 11.1.6-h32
>= 11.1.7, < 11.1.7-h6
>= 11.1.8, < 11.1.10-h25
>= 11.1.11, < 11.1.13-h5
>= 11.1.14, < 11.1.15
11.1.4-h33
11.1.6-h32
11.1.7-h6
11.1.10-h25
11.1.13-h5
11.1.15
10.2
>= 10.2.0, < 10.2.7-h34
>= 10.2.8, < 10.2.10-h36
>= 10.2.11, < 10.2.13-h21
>= 10.2.14, < 10.2.16-h7
>= 10.2.17, < 10.2.18-h6
10.2.7-h34
10.2.10-h36
10.2.13-h21
10.2.16-h7
10.2.18-h6

Versions not listed are stated unaffected by the vendor.

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 28 Sept 2026 at 21:17 UTC · Parser patcharo-cve5/1.1.0
NVD
NVD · 27 Sept 2026 at 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 30 Sept 2026 at 00:17 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026 at 21:17 UTC