In a fresh alert, Palo Alto Networks revealed a serious vulnerability in its PAN-OS software. Dubbed CVE-2026-0229, this denial-of-service (DoS) issue hits the Advanced DNS Security (ADNS) feature.
An unauthenticated attacker can send a specially crafted packet to force firewalls to reboot repeatedly. Keep hitting it, and the device enters maintenance mode, knocking it offline until fixed.
Published on February 11, 2026, the flaw carries a CVSS v4.0 base score of 6.6 (MEDIUM severity) and a broader CVSS-B score of 8.7. It’s rated with moderate urgency.
No malicious exploits are known yet, but the risk is real: attackers need no privileges, just network access. The weakness stems from CWE-754 (improper checks for unusual conditions) and CAPEC-153 (input manipulation).
This affects PAN-OS versions where ADNS is enabled with a spyware profile set to block, sinkhole, or alert traffic, not just allow it.
Good news? Cloud NGFW, Prisma Access, PAN-OS 11.1, and 10.2 are safe. Discovery came from an internal researcher, jliu@TikkalaSecurity.
| Aspect | Details |
|---|---|
| ID | CVE-2026-0229 |
| Severity | MEDIUM (CVSS 6.6 / CVSS-B 8.7) |
Attackers exploit ADNS by crafting malicious DNS packets. The firewall mishandles them, triggering an immediate reboot.
Spam enough packets, and it loops into maintenance mode, where manual intervention is needed. Recovery is user-dependent, with a moderate response effort. Automatable? Yes, scripts could hammer exposed firewalls.
Palo Alto urges immediate upgrades for vulnerable versions. Older, unsupported PAN-OS needs migration to fixed supported releases. No config tweaks or signatures block this, so patching is key.
Firewalls guard networks; downtime means blind spots for breaches. With low barriers (network access only, no user interaction), threat actors could target enterprises.
Think hospitals, banks, anywhere uptime counts. This joins a string of PAN-OS issues, stressing timely updates.
Stay vigilant: Check your PAN-OS version via the dashboard. Enable auto-updates if possible. For full details, visit Palo Alto’s security advisory.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
%20(1).webp?fit=1600,900&ssl=1)


