Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Heap-Based Buffer Overflow in PAN-OS DNS Proxy and DNS Server

IdentifiersCVE-2026-0264CWE-122· Heap-based Buffer Overflow

CVE-2026-0264 is a heap-based buffer overflow in the DNS Proxy and DNS Server features of Palo Alto Networks PAN-OS. An unauthenticated attacker with network access can send specially crafted DNS network traffic to trigger the overflow. According to the provided advisory content, exploitation affects PAN-OS platforms except Cloud NGFW and Prisma Access; Panorama is also not impacted. Successful exploitation causes a denial-of-service condition on affected PAN-OS platforms generally, while on PA-Series hardware firewalls the flaw may potentially permit arbitrary code execution.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

The primary impact is unauthenticated remote denial of service against affected PAN-OS systems exposing the vulnerable DNS Proxy or DNS Server functionality. On PA-Series hardware firewalls, the heap overflow may also enable arbitrary code execution, making the issue materially more severe on hardware appliances than on VM-Series platforms, where the provided content indicates exploitation is limited to denial of service.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure of the PAN-OS DNS Proxy and DNS Server features to untrusted networks and restrict which hosts can send DNS traffic to affected devices. Disable the vulnerable DNS Proxy or DNS Server functionality where operationally feasible until fixes are applied. The provided content specifically recommends reviewing Palo Alto Networks advisories and implementing the vendor-suggested mitigations.

Remediation

Patch, then assume compromise.

Apply Palo Alto Networks PAN-OS security updates released in the May 13, 2026 advisory cycle. The provided content indicates affected branches include PAN-OS 12.1, 11.2, 11.1, and 10.2, and specifically notes that PAN-OS 12.1 versions prior to 12.1.4-h5 and prior to 12.1.7 are affected. Administrators should review the vendor advisory for the exact fixed versions applicable to their deployed branch and upgrade accordingly.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Palo Alto NetworksPa-Serieshardware
Palo Alto NetworksPan-Osoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity9

Community discussion across Reddit, Mastodon, and other social sources.