Palo Alto Networks PAN-OS 12.1
Vulnerabilities, fixed releases, vendor recommendation and support status of the 12.1 branch, from official sources.
Patcharo matches 18 vulnerabilities against Palo Alto Networks PAN-OS 12.1: 6 critical, 2 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: 12.1.8. Last source modification: 11 Aug 2026.
Last verified by Patcharo: 30 Sept 2026 at 03:18 UTC
In brief
- Matched CVEs
- 18
- CISA KEV
- 2
- Newest fix stated
- 12.1.8
- Support
- No statement in the catalog
- Recommended maintenance build
- No official recommendation
- Recommended release
- No official recommendation
- CERT-FR
- 5 documents
Support status
From the vendor's published life-cycle policy; support is not a recommendation.
The life-cycle policy Patcharo reads states nothing about this branch.
Vendor recommendation
The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.
Palo Alto Networks publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.
Vulnerabilities affecting 12.1
Each record matched to this branch with the fixed release the source states, newest first.
| CVE | Severity | Fixed in | Published |
|---|---|---|---|
| CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass | High7.2CVSS 3.1, High | 12.1.4-h8, 12.1.7-h2 | |
| CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface | High7.1CVSS 3.1, High | 12.1.8 | |
| CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) | High7.2CVSS 3.1, High | 12.1.4-h8, 12.1.7-h2 | |
| CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) | Critical9.9CVSS 3.1, Critical | 12.1.4-h8, 12.1.7-h2 | |
| CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI | High7.2CVSS 3.1, High | 12.1.4-h8, 12.1.7-h2 | |
| CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing | High7.5CVSS 3.1, High | 12.1.4-h8, 12.1.7-h2 | |
| CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent | High7.5CVSS 3.1, High | 12.1.4-h8, 12.1.7-h2 | |
| CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI | High7.2CVSS 3.1, High | 12.1.4-h7, 12.1.7 | |
| CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) | High7.2CVSS 3.1, High | 12.1.4-h7 | |
| CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities | Critical9.1CVSS 3.1, CriticalKEVRansomware | 12.1.4-h6, 12.1.7 | |
| CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching | Critical9.1CVSS 3.1, Critical | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0261 PAN-OS: Authenticated Admin Command Injection Vulnerability | High7.2CVSS 3.1, High | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing | High7.5CVSS 3.1, High | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing | Critical9.8CVSS 3.1, Critical | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution | Critical9.8CVSS 3.1, Critical | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled | High8.1CVSS 3.1, High | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | Critical9.8CVSS 3.1, CriticalKEV | 12.1.4-h5, 12.1.7 | |
| CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal | High7.5CVSS 3.1, High | 12.1.3-h3 |
CERT-FR advisories and alerts
Documents of the French national CERT referencing these CVEs, newest first.
- Advisory (AVI)CERTFR-2026-AVI-0853Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 9 Jul 2026
- Advisory (AVI)CERTFR-2026-AVI-0734Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 11 Jun 2026
- Advisory (AVI)CERTFR-2026-AVI-0596Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 15 May 2026
- Advisory (AVI)CERTFR-2026-AVI-0537Vulnérabilité dans Palo Alto Networks User-ID Authentication PortalPublished 6 May 2026
- Advisory (AVI)CERTFR-2026-AVI-0049Multiples vulnérabilités dans les produits Palo Alto NetworksPublished 15 Jan 2026
How Patcharo reads this
Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.