Palo Alto Networks released patches for a critical vulnerability in its firewall platform. The flaw in question allowed for attackers to trigger a denial of service (DOS) based exploit.
Marked by Palo Alto with "moderate" urgency and a "high "severity score of 7.7, the flaw in its PAN-OS suite also sees repeated DOS attempts cause the firewall to enter into maintenance mode.
The vulnerability affects various PAN-OS versions, as well as some iterations of Prisma Access, with the issue only applicable to PAN-OS Next-Generation Firewall (NGFW) or Prisma Access configurations with an enabled GlobalProtect gateway or portal. The Cloud NGFW service was marked as safe from the exploit.
Users were recommended to download the latest upgrades from Palo Alto.
“We have successfully completed the Prisma Access upgrade for most of the customers, with the exception of few in progress due to conflicting upgrade schedules,” Palo Alto Networks advised. “Remaining customers are being promptly scheduled for an upgrade through our standard upgrade process.”
The software giant added it was not aware of any malicious exploitations at the time of its advisory.
The DOS issue follows another PAN-OS flaw which was patched in December. Marked as CVE-2025-4615, the vulnerability enabled an authenticated administrator to bypass system restrictions and execute arbitrary commands due to an improper input neutralization vulnerability in the firewall's management web interface.
Comments