
Looks like PANW finally patched the downgrade attack used by @AmberWolfSec 's NachoVPN. Another favourite IA vector lost. 🥲 No mention of AmberWolf in the acknowledgements, though... https://security.paloaltonetworks.com/CVE-2026-0299
Post summary
The tweet announces that Palo Alto Networks has released a patch for CVE-2026-0299, a downgrade attack used by NachoVPN, and highlights that the vulnerability is now resolved.



