Summary
Palo Alto Networks released security updates on May 14, 2026, addressing three critical vulnerabilities in PAN-OS as part of its monthly Patch Wednesday cycle. The flaws — CVE-2026-0263, CVE-2026-0264, and CVE-2026-0265 — affect PA-Series and VM-Series firewalls and could allow unauthenticated attackers to achieve arbitrary code execution with elevated privileges, cause denial of service, or bypass authentication controls.
CVE-2026-0263 is a buffer overflow in IKEv2 processing that enables unauthenticated remote code execution. CVE-2026-0264 is a heap-based buffer overflow in the DNS Proxy and DNS Server features, allowing arbitrary code execution on PA-Series hardware or denial of service on VM-Series. CVE-2026-0265 is an authentication bypass that affects firewalls and Panorama appliances with Cloud Authentication Service (CAS) enabled.
Affected versions span PAN-OS 10.2, 11.1, 11.2, and 12.1. Singapore’s Cyber Security Agency (CSA) and other national CERTs have issued advisories urging immediate patching.
Sources
- CSA Singapore — Critical Vulnerabilities in Palo Alto Networks PAN-OS
- Palo Alto Networks Security Advisories
Commentary
Palo Alto Networks firewalls are everywhere in enterprise environments, which makes these vulnerabilities particularly dangerous. The IKEv2 buffer overflow (CVE-2026-0263) is especially concerning — IKEv2 is used for VPN tunnel establishment, meaning the vulnerable surface is typically internet-facing by design. An unauthenticated RCE on a firewall is about as bad as it gets in terms of network security.
This comes on the heels of the CVE-2026-0300 zero-day that was under active state-sponsored exploitation earlier this month. PAN-OS administrators should be treating every patch cycle as urgent at this point — the platform has become a high-value target for both nation-state and criminal actors. If you are running any of the affected versions, patch now, not after the change window.
