CVE-2026-0280 LOW

CVE-2026-0280: PAN-OS: IPv6 Firewall Policy Bypass

Vendor Palo Alto Networks
Product PAN-OS
Weakness CWE-131
Published July 9, 2026
Last update July 9, 2026

CVSS base score

1.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/AU:Y/V:D/RE:M/U:Amber

What the vulnerability does

01Description

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.

Key dates

02Disclosure timeline

July 9, 2026 CVE published
July 9, 2026 Record updated