Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Palo Alto Networks Firewall Vulnerability

A critical denial-of-service (DoS) flaw in Palo Alto Networks’ PAN-OS software could let unauthenticated attackers crash firewalls into endless reboot cycles, potentially crippling enterprise networks.

Dubbed CVE-2026-0229, the vulnerability lurks in the Advanced DNS Security (ADNS) feature. An attacker sends a maliciously crafted packet to trigger a system reboot.

Repeated exploitation forces the firewall into maintenance mode, halting traffic inspection and exposing organizations to outages. Cloud NGFW and Prisma Access remain unaffected.

Palo Alto Networks detailed the issue in a security advisory, confirming that it affects only specific PAN-OS versions when ADNS is enabled alongside a spyware profile set to block, sinkhole, or alert traffic.

Affected Versions and Fixes

Product Affected Versions Fixed Versions
PAN-OS 12.1 < 12.1.4 (specifically 12.1.2–12.1.3) ≥ 12.1.4
PAN-OS 11.2 < 11.2.10 (11.2.0–11.2.9) ≥ 11.2.10
PAN-OS 11.1 None All
PAN-OS 10.2 None All
Cloud NGFW None All
Prisma Access None All

The company urges admins to upgrade vulnerable systems immediately. Older, unsupported PAN-OS versions should migrate to a patched release. No workarounds exist, and Threat Prevention signatures can’t detect exploits due to the vulnerability’s design.

Palo Alto reports no known exploitation in the wild. Still, security experts warn of risks in high-traffic environments. “DoS flaws like this can cascade into major disruptions, especially if chained with other attacks. Organizations relying on Palo Alto for perimeter defense must prioritize patching.

Firewalls with ADNS form a key line of defense against DNS-based threats, making this exposure particularly concerning for enterprises blocking malicious domains. Admins should verify configurations and scan for unpatched systems via Palo Alto’s support portal.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.