CVE-2026-0229Disclosure

LOWCVSS 6.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 12 signals
  • Disclosure: 11 classified signals
  • Peaked 4d ago at 5 mentions (2026-02-12); latest day: 1
  • 12 total mentions across 6 days

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-02-11: 1Mentions · 2026-02-12: 5Mentions · 2026-02-13: 3Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-03-20: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 5Technical Details · 2026-02-13: 3Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-20: 102-1102-1202-1302-1902-2003-20
Signal classification2 categories
Disclosure
1191.7%
Patch
18.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-125
Disclosure4Patch1
2026-02-133
Disclosure3
2026-02-191
Disclosure1
2026-02-201
Disclosure1
2026-03-201
Disclosure1
Full discourse12 posts
  • VulnTracker@vuln_tracker
    Disclosure

    Palo Alto PAN-OS DoS vulnerability (CVE-2026-0229) can trigger firewall reboot loops via Advanced DNS Security (ADNS). Affected: PAN-OS 12.1 < 12.1.4 PAN-OS 11.2 < 11.2.10 Full breakdown: https://vulntracker.io/blog/palo-alto-pan-os-cve-2026-0229-firewall-reboot-loops/

    Post summary

    The post announces a DoS flaw in Palo Alto PAN‑OS (CVE‑2026‑0229) that triggers reboot loops through ADNS on certain OS versions, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00050190
    333 followersView on X
  • まっちゃだいふく@ripjyr
    Disclosure

    Paloaltoの脆弱性情報 「CVE-2026-0229 PAN-OS: Denial of Service in Advanced DNS Security Feature (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0229

    Post summary

    A new CVE-2026-0229 vulnerability in Palo Alto Networks PAN-OS that causes a denial of service in the Advanced DNS Security Feature has been publicly disclosed with medium severity. No exploit or mitigation details are provided.

    001303.0K
    8.6K followersView on X
  • キタきつね@foxbook
    Disclosure

    認証されていない攻撃者が Palo Alto ファイアウォールをメンテナンスモードループに陥らせる可能性がある (CVE-2026-0229) Unauthenticated Attacker Can Trap Palo Alto Firewalls in Maintenance Mode Loop (CVE-2026-0229) #DailyCyberSecurity (Feb 12) https://securityonline.info/crash-loop-palo-alto-networks-flaw-cve-2026-0229-forces-maintenance-mode/

    Post summary

    The post announces CVE‑2026‑0229, a flaw allowing unauthenticated attackers to trap Palo Alto firewalls in a maintenance‑mode loop, effectively causing a denial‑of‑service condition.

    00020298
    4.7K followersView on X
  • まっちゃだいふく@ripjyr
    Disclosure

    Paloaltoの脆弱性情報 「CVE-2026-0229 PAN-OS: Denial of Service in Advanced DNS Security Feature (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0229

    Post summary

    An advisory has been published announcing CVE-2026-0229, a medium‑severity DoS vulnerability in Palo Alto Networks' PAN‑OS Advanced DNS Security feature.

    00010420
    8.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Palo Alto Networks ファイアウォールの脆弱性 CVE-2026-0229 が FIX:再起動ループと DoS 攻撃 https://iototsecnews.jp/2026/02/12/palo-alto-networks-firewall-vulnerability-allows-an-attacker-to-force-firewalls-into-a-reboot-loop/ Palo Alto Networks の PAN-OS に、サービス停止を引き起こす深刻な脆弱性が発見されました。この問題の原因は、PAN-OS の高度な DNS 保護機能 (ADNS) において、受信した DNS パケットを処理する際の検証の不備にあります。攻撃者が特別に細工した DNS パケットを送信すると、ADNS を構成するプロセスが予期しない動作を起こし、システムの再起動が誘発されます。ご利用のチームは、ご注意ください。 #CVE20260229 #PaloAlto #Vulnerability

    Post summary

    The post announces a severe PAN‑OS DNS‑based vulnerability (CVE‑2026‑0229) that can trigger reboot loops and DoS, but it does not provide PoC, exploit code, active exploitation evidence, or patch details.

    01000137
    484 followersView on X
  • Yu F@fj_twt
    Disclosure

    PAN-OS Advanced DNS Security (ADNS) 機能に脆弱性、悪意のある細工されたDNSリクエストでシステム再起動。再起動繰り返した結果メンテモードにおちる… ( ꒪⌓꒪)…PANOSコロリか… CVE-2026-0229 PAN-OS: Denial of Service in Advanced DNS Security Feature https://security.paloaltonetworks.com/CVE-2026-0229

    Post summary

    The post reports CVE‑2026‑0229, a DoS flaw in PAN‑OS Advanced DNS Security that causes system restarts through crafted DNS requests, and links to the official Palo Alto Networks advisory.

    00010257
    1.4K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #ADNS Unauthenticated Attacker Can Trap Palo Alto Firewalls in Maintenance Mode Loop (CVE-2026-0229) https://securityonline.info/crash-loop-palo-alto-networks-flaw-cve-2026-0229-forces-maintenance-mode/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A new CVE-2026-0229 vulnerability allows unauthenticated attackers to trap Palo Alto firewalls in a maintenance mode loop, as reported in a vulnerability announcement.

    0000051
    1.5K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Unauthenticated Attacker Can Trap Palo Alto Firewalls in Maintenance Mode Loop (CVE-2026-0229) https://securityonline.info/crash-loop-palo-alto-networks-flaw-cve-2026-0229-forces-maintenance-mode/

    Post summary

    A new vulnerability (CVE-2026-0229) has been disclosed, allowing unauthenticated attackers to trap Palo Alto firewalls into a maintenance mode loop.

    0000051
    73 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    パロアルトネットワークス、PAN-OSのAdvanced DNS SecurityにDoS脆弱性(CVE-2026-0229) https://rocket-boys.co.jp/security-measures-lab/palo-alto-networks-pan-os-advanced-dns-security-dos-vulnerability-cve-2026-0229/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    An article announces a DoS vulnerability (CVE‑2026‑0229) affecting Palo Alto Networks PAN‑OS Advanced DNS Security, with no PoC, exploit code, or patch details provided.

    00000159
    318 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Palo Alto PAN-OS ADNS Bug Lets Attackers Force Firewall Reboot Loops (CVE-2026-0229) Palo Alto Networks warns an unauthenticated attacker can send crafted packets to PAN-OS Advanced DNS Security (ADNS) and repeatedly reboot affected firewalls—potentially driving them into maintenance mode and causing sustained outages if ADNS spyware profiles are set to block/sinkhole/alert. This matters because perimeter downtime creates blind spots and business disruption, and there’s no mitigation besides upgrading to fixed supported releases. 🎯 Target: Global / PAN-OS Firewalls (ADNS enabled) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/palo-alto-networks-firewall-vulnerability/

    Post summary

    Palo Alto Networks warns that CVE‑2026‑0229 allows unauthenticated attackers to trigger repeated firewall reboots via crafted ADNS packets; the only mitigation is upgrading to a fixed release.

    0000076
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Palo Alto PAN-OS DoS Bug Can Trap Firewalls in a Remote Reboot Loop (CVE-2026-0229) A flaw in PAN-OS Advanced DNS Security (ADNS) lets unauthenticated attackers trigger repeated reboots with crafted packets, potentially forcing devices into maintenance mode and causing sustained outages; Cloud NGFW and Prisma Access are reportedly unaffected. This matters because it’s a low-friction availability attack against perimeter enforcement points, turning a single bug into wide business disruption. 🎯 Target: Global / Organizations running PAN-OS firewalls with ADNS enabled #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/palo-alto-networks-firewall-reboot-loop/

    Post summary

    A newly disclosed CVE‑2026‑0229 DoS bug in Palo Alto Networks' PAN‑OS Advanced DNS Security allows unauthenticated attackers to force firewalls into a reboot loop, potentially causing widespread outages.

    0000069
    191 followersView on X
  • 趣テクノロジー@omomuki_tech
    Disclosure

    Palo Alto Networks社のファイアウォール製品で利用されているPAN-OSソフトウェアに、深刻なサービス拒否(DoS)の脆弱性(CVE-2026-0229)が発見されました。 この脆弱性を悪用されると、認証されていない攻撃者がファイアウォールを無限に再起動させ続ける「再起動ループ」に陥らせることが可能です。原因は、Advanced DNS Security (ADNS) という機能に存在しており、攻撃者が悪意を持って作成したパケットを送りつけるだけで、システムの再起動が引き起こされます。 この攻撃が繰り返し行われると、ファイアウォールは正常に機能しなくなり、企業ネットワーク全体が停止してしまうなど、深刻な影響が出る恐れがあります。 #サイバーセキュリティ #脆弱性 #PaloAltoNetworks https://cybersecuritynews.com/palo-alto-networks-firewall-reboot-loop/

    Post summary

    A critical DoS vulnerability (CVE‑2026‑0229) was discovered in Palo Alto Networks PAN‑OS, enabling unauthenticated attackers to cause infinite reboot loops by sending crafted ADNS packets.

    0000054
    239 followersView on X

Explore more