Palo Alto fixes three high-severity PAN-OS vulnerabilities
Palo Alto Networks has published security updates for several PAN-OS vulnerabilities. Three carry a CVSS score of 7.2 and may, under certain conditions, allow remote code execution or authentication bypass: CVE-2026-0263 in IKEv2 processing, CVE-2026-0264 in DNS Proxy and DNS Server, and CVE-2026-0265 tied to the Cloud Authentication Service. At the time of publication, the vendor stated that no evidence of active exploitation had been observed.
What this means for your organisation
The firewall is the component many organisations treat as the boundary between inside and outside. If it falls, a whole set of assumptions in your risk picture falls with it. The absence of observed exploitation today only means the clock is running: flaws in exposed security appliances are routinely reverse-engineered out of the patches within days. For organisations in scope of NIS2, orderly and documented patching of this kind of equipment is exactly what a supervisory authority will look for.
Berigo recommends
- Schedule the PAN-OS update now, while you can still do it in a maintenance window of your own choosing.
- Check whether IKEv2, DNS proxy and Cloud Authentication Service are actually in use, and disable what you do not need.
- Restrict the firewall management interface so it is not reachable from the internet.
- Record when the update was applied and by whom, so the trail can be shown later.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch