CVE-2026-0263
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on...
Affects 0 products across 6 vendors.
Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.
A low severity vulnerability affects Cloud systems (CVE-2026-0263). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
BSID: BS-2026-GLOBAL-059151-I • Model: rule-based-v1 • Confidence: LOW
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-0263?
What is the CVSS score for CVE-2026-0263?
Is CVE-2026-0263 actively exploited?
How do I remediate CVE-2026-0263?
What systems are affected by CVE-2026-0263?
| CVE ID | CVE-2026-0263 |
|---|---|
| BSID | BS-2026-GLOBAL-059151-I BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-05-13 |
| Last Modified | 2026-07-14 |
| ICS Relevance | 80% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.
Source: NIST NVD / MITRE CVE Database
Vulnerability details: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities. CVSS vector: Not available.
Exploitation Likelihood: MINIMAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cloud | — | — |
| Palo Alto | — | — |
| Palo Alto Networks | — | — |
| Panorama | — | — |
| Prisma | — | — |
| Processing | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | rule-based-v1 |
|---|---|
| Confidence | LOW |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 89e298e1061067b8564a1cca8601caf322f1978bb2d69d20bbb7965d6dfdb4226d330ee5cd012c88a8e0900ce9d5500821e822fc2f4ee256e0df46444f0c55b4 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →