CVE-2026-0263

CRITICAL

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on...

Affects 0 products across 6 vendors.

BCS3.46
CVSS 3.19.8
CVSS v47.2
EPSS0.4%
Percentile30th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

A low severity vulnerability affects Cloud systems (CVE-2026-0263). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-059151-I • Model: rule-based-v1 • Confidence: LOW

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0263?
A low severity vulnerability affects Cloud systems (CVE-2026-0263). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-0263?
CVE-2026-0263 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-0263 actively exploited?
No confirmed active exploitation of CVE-2026-0263 as of 2026-07-15.
How do I remediate CVE-2026-0263?
Priority: MONITOR. PSIRT: [email protected]
What systems are affected by CVE-2026-0263?
CVE-2026-0263 affects: Cloud, Palo Alto, Palo Alto Networks, Panorama, Prisma, Processing.
Vulnerability Details
CVE IDCVE-2026-0263
BSIDBS-2026-GLOBAL-059151-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-13
Last Modified2026-07-14
ICS Relevance80%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities. CVSS vector: Not available.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Cloud —
Palo Alto —
Palo Alto Networks —
Panorama —
Prisma —
Processing —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 89 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceLOW
Enriched At2026-05-24
SHA-512 Audit Hash89e298e1061067b8564a1cca8601caf322f1978bb2d69d20bbb7965d6dfdb4226d330ee5cd012c88a8e0900ce9d5500821e822fc2f4ee256e0df46444f0c55b4
Related CVEs affecting Cloud
CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2025-54122 10.0 Manager-io/Manager is accounting software. A critical unauthenticated full re... CVE-2025-64180 10.0 Manager-io/Manager is accounting software. In Manager Desktop and Server vers... CVE-2026-0501 9.9 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Prem... CVE-2025-47282 9.9 Gardener External DNS Management is an environment to manage external DNS ent...
View all Cloud CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →