Palo Alto PAN-OS Vulnerability (CVE-2026-0229) Can Trigger Firewall Reboot Loops
A denial-of-service vulnerability in PAN-OS Advanced DNS Security (CVE-2026-0229) allows unauthenticated attackers to force firewalls into repeated reboot cycles, potentially pushing them into maintenance mode. Upgrade affected PAN-OS versions immediately.
TL;DR
A denial-of-service vulnerability affecting Palo Alto Networks PAN-OS has been disclosed under CVE-2026-0229. The flaw exists within the Advanced DNS Security (ADNS) feature and could allow unauthenticated attackers to force firewalls into repeated reboot cycles. Upgrade affected PAN-OS versions immediately.
What's the Issue?
The vulnerability allows an attacker to send a maliciously crafted packet that triggers a system reboot. Repeated exploitation can push the firewall into maintenance mode, disrupting traffic inspection and potentially impacting enterprise network availability.
This issue only affects PAN-OS when:
- Advanced DNS Security (ADNS) is enabled
- A spyware profile is configured to block, sinkhole, or alert traffic
Cloud NGFW and Prisma Access are not impacted.
Affected Versions
| PAN-OS Version | Status |
|---|---|
| PAN-OS 12.1 | Affected — versions prior to 12.1.4 (12.1.2–12.1.3) |
| PAN-OS 11.2 | Affected — versions prior to 11.2.10 (11.2.0–11.2.9) |
| PAN-OS 11.1 | Not affected |
| PAN-OS 10.2 | Not affected |
Fix and Mitigation
Palo Alto Networks urges administrators to upgrade to patched versions immediately.
Important considerations:
- No available workarounds — there is no configuration change that mitigates the issue without upgrading
- No Threat Prevention signatures capable of detecting exploitation due to the vulnerability's design
While no in-the-wild exploitation has been reported so far, denial-of-service vulnerabilities in perimeter security devices should be treated with urgency.
Recommended Actions
- Verify whether ADNS is enabled in your environment
- Audit deployed PAN-OS versions across your infrastructure
- Upgrade affected systems to patched releases (12.1.4+ or 11.2.10+)
- Migrate unsupported versions to maintained branches
Why This Matters
Denial-of-service vulnerabilities in firewalls are particularly dangerous because they directly impact the security boundary of your network. A firewall stuck in a reboot loop or forced into maintenance mode means:
- Traffic inspection stops
- Security policies may not be enforced
- Network availability is disrupted
- Attackers could use the window to launch secondary attacks
Even though this vulnerability doesn't allow code execution, its impact on availability makes it critical for any organization running affected PAN-OS versions.
Stay Ahead
Vulnerabilities like CVE-2026-0229 are a reminder that even well-known, widely deployed security products are not immune to critical flaws. The organizations that respond fastest are the ones with systems in place to catch these disclosures the moment they happen.
Track CVE-2026-0229 and get notified of updates:
View CVE-2026-0229 on VulnTracker →