Palo Alto Networks has released security updates to fix a critical vulnerability in GlobalProtect Gateway and Portal that could lead to a denial-of-service (DoS) condition. The flaw, tracked as CVE-2026-0227 with a CVSS score of 7.7, has a publicly available proof-of-concept (PoC) exploit.
According to the advisory, the vulnerability stems from an improper check for exceptional conditions (CWE-754). Repeated exploitation attempts can cause the affected firewall to enter maintenance mode, disrupting network operations.
Affected Versions
The flaw impacts several PAN-OS and Prisma Access releases:
PAN-OS 12.1: <12.1.3-h3, <12.1.4
PAN-OS 11.2: <11.2.4-h15, <11.2.7-h8, <11.2.10-h2
PAN-OS 11.1: <11.1.4-h27, <11.1.6-h23, <11.1.10-h9, <11.1.13
PAN-OS 10.2: <10.2.7-h32, <10.2.10-h30, <10.2.13-h18, <10.2.16-h6, <10.2.18-h1
PAN-OS 10.1: <10.1.14-h20
Prisma Access 11.2: <11.2.7-h8
Prisma Access 10.2: <10.2.10-h29
The vulnerability only affects PAN-OS NGFW or Prisma Access deployments with an enabled GlobalProtect gateway or portal. Other Palo Alto NGFW configurations are not impacted.
Safety Suggestions
According to Palo Alto Networks, administrators should install these updates without delay because there is no alternative method to fix this vulnerability. Even though there is no indication that this has been abused in real-world applications yet, the GlobalProtect Gateways that expose themselves to the Internet have undergone regular scans in the last year, which increases the likelihood of abuse.
"The vulnerability allows an attacker who does not have proper identification or credentials to exploit it and prevent service to other users, which creates a situation where a network may become unavailable," according to the advisory provided by Palo Alto Networks.
All organizations utilizing the GlobalProtect Portal or Gateway must examine their current version of PAN-OS, focus their efforts on finding time to patch any software identified as having the identified vulnerability, and watch for unusual patterns or behaviors to prevent loss of service to their customers.
Source: The Hacker News