Palo Alto Networks PAN-OS and Prisma Access unauthenticated DoS flaw (CVE-2026-0227)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-0227 affects Palo Alto Networks PAN-OS 10.1 or later and Prisma Access with GlobalProtect enabled, creating an unauthenticated DoS risk that can push firewalls into maintenance mode. Palo Alto Networks has released fixes for the flaw, and most cloud Prisma Access instances have already been patched. The issue matters because exposed firewalls can lose protections even without attacker authentication, although the vendor had no evidence of active exploitation at publication.
Related Happenings
Palo Alto Networks GlobalProtect log search guidance for CVE-2026-0257
Advisory/Mitigation
H score35
First: 15.06.2026 09:17
Last: 15.06.2026 09:17
Sources 1
About this happening:
Palo Alto Networks is urging GlobalProtect customers to search logs for successful gateway-connected events tied to CVE-2026-0257, a step that can expose possible unau...
Palo Alto Networks GlobalProtect log search guidance for CVE-2026-0257
Advisory/MitigationAbout this happening: Palo Alto Networks is urging GlobalProtect customers to search logs for successful gateway-connected events tied to CVE-2026-0257, a step that can expose possible unau...
PAN-OS User-ID Authentication Portal mitigation guidance (CVE-2026-0300)
Advisory/Mitigation
H score77
First: 06.05.2026 09:14
Last: 06.05.2026 09:14
Sources 1
About this happening:
Palo Alto Networks issued mitigation guidance for CVE-2026-0300 after the PAN-OS User-ID Authentication Portal flaw was reported exploited in the wild, leaving pub...
PAN-OS User-ID Authentication Portal mitigation guidance (CVE-2026-0300)
Advisory/MitigationAbout this happening: Palo Alto Networks issued mitigation guidance for CVE-2026-0300 after the PAN-OS User-ID Authentication Portal flaw was reported exploited in the wild, leaving pub...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware Activity
H score33
First: 23.04.2026 15:00
Last: 23.04.2026 15:00
Sources 1
About this happening:
CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware ActivityAbout this happening: CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
Latest development: 24.04.2026 23:34
CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.
CISA end-of-support edge device decommissioning mandate (BOD 26-02)
Advisory/Mitigation
H score46
First: 06.02.2026 10:41
Last: 06.02.2026 10:41
Sources 1
About this happening:
CISA's BOD 26-02 now forces U.S. federal agencies to inventory, decommission, and replace end-of-support edge devices that no longer receive security updates. The dire...
CISA end-of-support edge device decommissioning mandate (BOD 26-02)
Advisory/MitigationAbout this happening: CISA's BOD 26-02 now forces U.S. federal agencies to inventory, decommission, and replace end-of-support edge devices that no longer receive security updates. The dire...
CISA orders federal agencies to remediate end-of-support edge devices
Public Sector Action
H score26
First: 05.02.2026 14:00
Last: 05.02.2026 14:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-02 to require FCEB agencies to inventory, update, and remove end-of-support edge devices within a specified timeframe....
CISA orders federal agencies to remediate end-of-support edge devices
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-02 to require FCEB agencies to inventory, update, and remove end-of-support edge devices within a specified timeframe....
Timeline
-
15.01.2026 11:02 2 articles · 6mo ago
Palo Alto Networks patches CVE-2026-0227 in PAN-OS and Prisma Access
Mitigation Patch UpdatePalo Alto Networks releases fixes for CVE-2026-0227, a high-severity PAN-OS vulnerability affecting PAN-OS 10.1 or later and Prisma Access configurations when the GlobalProtect gateway or portal is enabled. Repeated unauthenticated triggering can force firewalls into maintenance mode and disable firewall protections, and the vendor says most cloud Prisma Access instances are already patched while remaining customers are being scheduled for upgrade.
Show sources
- Palo Alto Networks warns of DoS bug letting hackers disable firewalls — www.bleepingcomputer.com — 15.01.2026 11:02
- Palo Alto Networks warns of DoS bug letting hackers disable firewalls — www.bleepingcomputer.com — 15.01.2026 11:02