Status: UPDATED | Advisory ID: CVE-2026-0280
| CVE | CVE-2026-0280 |
| CVSS Score / Version | 7.2 (High) / CVSS v3.1 |
| Updated | 2026-08-11 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is none. |
| Affected products | Palo Alto Networks Prisma Access, Palo Alto Networks PAN-OS, and Siemens RUGGEDCOM APE1808 |
| Classified as | CWE-131 (Incorrect Calculation of Buffer Size) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Palo Alto Networks | Prisma Access | ||
| Palo Alto Networks | PAN-OS | ||
| Siemens | RUGGEDCOM APE1808 |
| Subsystems | General OT |
| Sectors | Multi-sector |
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability. (NVD)
Monitor Palo Alto Networks's and Siemens's web pages for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-0280 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-0280 |
| Vendor advisory | https://security.paloaltonetworks.com/CVE-2026-0280 |