CVE-2026-0263

CRITICALCVSS 9.8/10EPSS 0.31%

Last modified

CVE-2026-0263 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
PaloaltonetworksPan-Os>= 11.1.0, < 11.1.4
PaloaltonetworksPan-Os>= 11.1.5, < 11.1.6
PaloaltonetworksPan-Os>= 11.1.8, < 11.1.10
PaloaltonetworksPan-Os>= 11.1.11, < 11.1.13
PaloaltonetworksPan-Os11.1.4
PaloaltonetworksPan-Os11.1.6
PaloaltonetworksPan-Os11.1.7
PaloaltonetworksPan-Os11.1.10
PaloaltonetworksPan-Os11.1.13
PaloaltonetworksPan-Os11.1.14
PaloaltonetworksPan-Os>= 11.2.0, < 11.2.4
PaloaltonetworksPan-Os>= 11.2.5, < 11.2.7
PaloaltonetworksPan-Os>= 11.2.8, < 11.2.10
PaloaltonetworksPan-Os11.2.4
PaloaltonetworksPan-Os11.2.7
PaloaltonetworksPan-Os11.2.10
PaloaltonetworksPan-Os11.2.11
PaloaltonetworksPan-Os>= 12.1.0, < 12.1.4
PaloaltonetworksPan-Os>= 12.1.5, < 12.1.7
PaloaltonetworksPan-Os12.1.4

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-0263?
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.
How severe is CVE-2026-0263?
CVE-2026-0263 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2026-0263?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-0263?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST