← All Advisories

CVE-2026-0280

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-0280

Key Details

CVECVE-2026-0280
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-08-11
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is none.
Affected productsPalo Alto Networks Prisma Access, Palo Alto Networks PAN-OS, and Siemens RUGGEDCOM APE1808
Classified asCWE-131 (Incorrect Calculation of Buffer Size)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksPrisma Access
Palo Alto NetworksPAN-OS
SiemensRUGGEDCOM APE1808
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.

Cloud NGFW and Panorama are not impacted by this vulnerability. (NVD)

What to Do

Monitor Palo Alto Networks's and Siemens's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0280
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0280
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0280