Summary

Palo Alto Networks released security updates on May 14, 2026, addressing three critical vulnerabilities in PAN-OS as part of its monthly Patch Wednesday cycle. The flaws — CVE-2026-0263, CVE-2026-0264, and CVE-2026-0265 — affect PA-Series and VM-Series firewalls and could allow unauthenticated attackers to achieve arbitrary code execution with elevated privileges, cause denial of service, or bypass authentication controls.

CVE-2026-0263 is a buffer overflow in IKEv2 processing that enables unauthenticated remote code execution. CVE-2026-0264 is a heap-based buffer overflow in the DNS Proxy and DNS Server features, allowing arbitrary code execution on PA-Series hardware or denial of service on VM-Series. CVE-2026-0265 is an authentication bypass that affects firewalls and Panorama appliances with Cloud Authentication Service (CAS) enabled.

Affected versions span PAN-OS 10.2, 11.1, 11.2, and 12.1. Singapore’s Cyber Security Agency (CSA) and other national CERTs have issued advisories urging immediate patching.

Sources

Commentary

Palo Alto Networks firewalls are everywhere in enterprise environments, which makes these vulnerabilities particularly dangerous. The IKEv2 buffer overflow (CVE-2026-0263) is especially concerning — IKEv2 is used for VPN tunnel establishment, meaning the vulnerable surface is typically internet-facing by design. An unauthenticated RCE on a firewall is about as bad as it gets in terms of network security.

This comes on the heels of the CVE-2026-0300 zero-day that was under active state-sponsored exploitation earlier this month. PAN-OS administrators should be treating every patch cycle as urgent at this point — the platform has become a high-value target for both nation-state and criminal actors. If you are running any of the affected versions, patch now, not after the change window.

By Allan