CVE-2026-0280

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

Scoring

Severity
LOW
CVSS base score
1.7
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/AU:Y/V:D/RE:M/U:Amber
EPSS probability
0.31%
CWE
CWE-131
Published
2026-07-09
Last modified
2026-08-11

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs