Palo Alto releases a fix for a PAN-OS vulnerability

Palo Alto Networks has released security updates addressing CVE-2026-0288, a vulnerability affecting PAN-OS. Successful exploitation could allow an authenticated attacker to impact the confidentiality and integrity of affected systems under specific conditions. Customers should review the affected software versions and apply the relevant updates as soon as possible. Palo Alto has also published mitigation guidance for environments where immediate patching is not feasible. Organisations running PAN-OS should prioritise internet-facing firewalls and management interfaces.

What this means for your organisation

Requiring authentication lowers the severity but does not remove it. Attackers who have already obtained a valid account, often through phishing, use exactly this kind of weakness to widen their access. Where the firewall is the central control between zones, this is a system that deserves a shorter patching deadline than average.

Berigo recommends

  • Check which PAN-OS versions you run and schedule the update into the next change window.
  • Apply the vendor's mitigations if you cannot patch immediately, and record that decision in the risk register.
  • Remove internet exposure of the management interface.
  • Review who holds local accounts on the firewall and remove those no longer in use.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch