Palo Alto Networks released fixes for CVE-2026-0227, a high-severity denial-of-service vulnerability in PAN-OS that can be triggered by an unauthenticated attacker when the GlobalProtect gateway or portal is enabled on affected next-generation firewall and Prisma Access configurations. Repeated exploitation attempts can force impacted firewalls into maintenance mode, effectively disabling protections and causing service disruption; Palo Alto Networks stated there are no workarounds and advised upgrading to patched releases.
Reporting indicates a proof-of-concept (PoC) exploit exists, although Palo Alto Networks said it had no evidence of in-the-wild exploitation at the time of advisory publication. Exposure risk remains material given the large number of internet-facing Palo Alto Networks firewalls observed online (with Shadowserver tracking roughly 6,000 exposed devices) and ongoing scanning activity historically targeting exposed GlobalProtect endpoints; administrators should prioritize patching across affected PAN-OS and Prisma Access versions and validate whether GlobalProtect is enabled on externally reachable interfaces.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Coverage of the disclosure noted Shadowserver reporting nearly 6,000 Palo Alto Networks firewalls exposed online, though it was unclear how many were vulnerable or already patched. The reporting emphasized the risk to organizations with internet-accessible GlobalProtect services.
In its advisory, Palo Alto Networks stated that a proof-of-concept exploit for CVE-2026-0227 exists, but it had not observed exploitation in the wild at the time of disclosure. The company also noted there are no workarounds, making patching the primary mitigation.
Palo Alto Networks disclosed and released fixes for CVE-2026-0227, a high-severity denial-of-service flaw in PAN-OS GlobalProtect Gateway and Portal that can be triggered by an unauthenticated attacker. The bug affects supported PAN-OS and certain Prisma Access versions when GlobalProtect is enabled, and fixed releases were provided across multiple branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.