Palo Alto Networks PAN-OS Buffer Overflow Vulnerability in IKEv2 Processing Allowing Remote Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in the IKEv2 processing of Palo Alto Networks PAN-OS software. This vulnerability allows an unauthenticated, network-based attacker to execute arbitrary code with elevated privileges on the firewall or to cause a denial-of-service condition. The issue affects PAN-OS versions 11.1, 11.2, and 12.1, with specific vulnerable subversions. Notably, Panorama, Cloud NGFW, and Prisma Access are not impacted by this vulnerability.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution with elevated privileges on the affected firewall, or cause a denial-of-service condition.

Remediation

Users can upgrade to the latest versions of PAN-OS 11.1, 11.2, or 12.1, depending on their current version. For those using IKEv2 VPN, it is recommended to configure VPN tunnels with NIST-approved Post Quantum Cryptography ciphers.

Added: May 13, 2026, 7:57 PM
Updated: May 13, 2026, 7:57 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.4
remediation
8.3
relevance
8.2
threat
0.0
urgency
10.0
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.