From e64226ffd4fc380e101eabe3bf8f9c5da06f7afd Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Thu, 28 May 2026 08:11:36 -0500 Subject: [PATCH] Processed new files --- web/data/issues/PAN-OS/addressed/11.1.15.md | 176 ++++++++++++++++++++ web/data/issues/PAN-OS/addressed/11.2.12.md | 84 ++++++++++ web/data/products.json | 6 +- 3 files changed, 264 insertions(+), 2 deletions(-) create mode 100644 web/data/issues/PAN-OS/addressed/11.1.15.md create mode 100644 web/data/issues/PAN-OS/addressed/11.2.12.md diff --git a/web/data/issues/PAN-OS/addressed/11.1.15.md b/web/data/issues/PAN-OS/addressed/11.1.15.md new file mode 100644 index 0000000..9782982 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.15.md @@ -0,0 +1,176 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.15 +--- + +## BLANK-000000 + +Fixes were made to address the following CVEs: + +- [CVE-2026-0265](https://security.paloaltonetworks.com/CVE-2026-0265) +- [CVE-2026-0264](https://security.paloaltonetworks.com/CVE-2026-0264) +- [CVE-2026-0263](https://security.paloaltonetworks.com/CVE-2026-0263) +- [CVE-2026-0262](https://security.paloaltonetworks.com/CVE-2026-0262) +- [CVE-2026-0261](https://security.paloaltonetworks.com/CVE-2026-0261) +- [CVE-2026-0258](https://security.paloaltonetworks.com/CVE-2026-0258) +- [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) +- [CVE-2026-0256](https://security.paloaltonetworks.com/CVE-2026-0256) +- [CVE-2026-0259](https://security.paloaltonetworks.com/CVE-2026-0259) +- [CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300) + +## PAN-325120 + +Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports. + +## PAN-323243 + +Fixed an issue where a configd crash occurred when the **Policies > Security** view was updated or refreshed in the web interface. + +## PAN-322815 + +```caveat +VM-Series firewalls on Microsoft Azure environments only +``` + +Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted. + +## PAN-319557 + +Fixed an issue where graphical counters did not display correctly in the control plane or dataplane monitor logs. + +## PAN-318784 + +Fixed an issue where the firewall stopped processing traffic and all VPN tunnels went down even when the firewall remained in an active state, and the CLI became unresponsive. + +## PAN-318567 + +Fixed an issue where the OpenConfig plugin stopped working after a configuration update. + +## PAN-317583 + +Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state. + +## PAN-317466 + +Fixed an issue where SIP sessions stopped progressing after the firewall received fragmented packets, fragmented at header field. + +## PAN-317372 + +Fixed an issue where custom administrators received an **access denied** error when attempting to view specific policy rule details from the **Rule Shadow** tab after a push from Panorama, even when the administrator had permissions to view Security policy rules. + +## PAN-316631 + +Fixed an issue BGP sessions experienced short disruptions across all peers, interfaces, and slots when a multicast event persisted longer than the NGP negotiated hold timers. + +## PAN-315820 + +Fixed an issue where User-ID XML API requests took longer than expected to return a response, which caused the web interface and captive portal pages to respond slowly or fail to load. this occurred when sending XML API requests for IP address-to-user mapping. + +## PAN-314875 + +```caveat +PA-7500 firewalls only +``` + +Fixed an issue where firewall logs were not visible in the Strata Logging Service even though cloud logging was enabled and the firewall was successfully forwarding logs. + +## PAN-314752 + +Fixed an issue on Panorama where, after removing a scheduled configuration push, Panorama still initiated the push at its previously scheduled time. + +## PAN-314385 + +```caveat +Firewalls in active/passive HA clusters only +``` + +Fixed an issue where high dataplane CPU usage occurred and traffic offloading decreased when a failover occurred from the active firewall to the passive firewall, and then back to the active firewall. + +## PAN-314126 + +Fixed an issue where session rematch did not properly apply updated Security policy rules to existing traffic flows after committing changes, which caused traffic to still be allowed when a new Security policy was set to **Deny**. + +## PAN-314020 + +Fixed an issue where the firewall did not decapsulate GENEVE packets when DNS Security retransmitted a DNS query after receiving a verdict from the cloud. + +## PAN-313828 + +Fixed an issue where the firewall did not forward traffic due to memory issues on a forwarding component. + +## PAN-313827 + +Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API. + +## PAN-313711 + +Fixed an issue where the show system environmentals power CLI command displayed duplicate slot names and associated voltage values. + +## PAN-313700 + +Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile. + +## PAN-313193 + +```caveat +Firewalls in Layer 2 mode only +``` + +) Fixed an issue where the new sessions were not able to be established due to the firewall intermittently dropping valid MAC address entries for specific VLANs when a manual switchover sent a high volume of traffic to the firewall. + +## PAN-311248 + +Fixed an issue where the ABR failed to translate and advertise the default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF backbone area as a Type-5 LSA. + +## PAN-310472 + +Fixed an issue on the web interface where checkboxes for **default information originate** and ABR in OSPF NSSA configurations were automatically enabled which resulted in unexpected configuration changes. + +## PAN-307470 + +Fixed an issue where an External Dynamic List (EDL) fetch with an invalid certificate was skipped on newly provisioned GlobalProtect gateway instances. + +## PAN-298960 + +Fixed an issue where the firewall continuously rebooted when the useridd process repeatedly restarted. + +## PAN-295309 + +Fixed an issue where OSPF session using MD5 authentication experienced intermittent flapping due to out-of-order packet processing. + +## PAN-294001 + +Fixed an issue on Panorama managed firewalls generated **Failed in get_pwchange_required** error messages in the authd logs for local administators. + +## PAN-293142 + +Fixed an issue where firewall components became unresponsive during sustained operation. + +## PAN-289706 + +Fixed an issue where the authd process crashed intermittently on VM-Series firewalls due to authentication sequence failures. The crashes occurred during memory management operations within a library while releasing memory to its central cache. + +## PAN-285213 + +Fixed an issue where proxy requests for certificate status (OCSP/CRL) from sslmgr contained incorrect values that caused unknown certificates to be blocked. + +## PAN-282335 + +Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled. + +## PAN-273805 + +Fixed an issue where SAML authentication for GlobalProtect failed when the GlobalProtect portal was accessed externally on a non-standard port. + +## PAN-271412 + +Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as **#43;** on the GlobalProtect client after upgrading to a PAN-OS 10.2 release. + +## PAN-257879 + +Fixed an issue where, after a system event, selecting a configuration file from maintenance mode loaded the incorrect configuration. + +## PAN-236914 + +Fixed an issue where TCP MSS adjustment did not function as expected for GRE tunnels when TCP SYN or SYN-ACK packets that were received had an MMS higher than 1460 bytes. diff --git a/web/data/issues/PAN-OS/addressed/11.2.12.md b/web/data/issues/PAN-OS/addressed/11.2.12.md new file mode 100644 index 0000000..28be39c --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.2.12.md @@ -0,0 +1,84 @@ +--- +type: Addressed +product: PAN-OS +version: 11.2.12 +--- + +## BLANK-000000 + +Fixes were made to address the following CVEs: + +- [CVE-2026-0265](https://security.paloaltonetworks.com/CVE-2026-0265) +- [CVE-2026-0264](https://security.paloaltonetworks.com/CVE-2026-0264) +- [CVE-2026-0263](https://security.paloaltonetworks.com/CVE-2026-0263) +- [CVE-2026-0262](https://security.paloaltonetworks.com/CVE-2026-0262) +- [CVE-2026-0261](https://security.paloaltonetworks.com/CVE-2026-0261) +- [CVE-2026-0258](https://security.paloaltonetworks.com/CVE-2026-0258) +- [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) +- [CVE-2026-0256](https://security.paloaltonetworks.com/CVE-2026-0256) +- [CVE-2026-0259](https://security.paloaltonetworks.com/CVE-2026-0259) +- [CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300) + +## PAN-325120 + +Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports. + +## PAN-322815 + +```caveat +VM-Series firewalls on Microsoft Azure environments only +``` + +Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted. + +## PAN-318275 + +```caveat +VM-Series firewalls only +``` + +Fixed an issue where the firewall became unresponsive and did not automatically reboot, which led to prolonged outages. With this fix, the Linux kernel configuration will trigger a system panic and reboot. + +## PAN-317583 + +Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state. + +## PAN-315912 + +Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized. + +## PAN-315176 + +Added an enable and disable CLI command to address an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic. + +## PAN-314319 + +Added a CLI command to enable and disable AHO software offload optimization. + +## PAN-314147 + +Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU. + +## PAN-314018 + +```caveat +VM-Series firewalls in AWS environments only +``` + +Fixed an issue where the decrypt mirror port did not function expected, which prevented decrypted traffic from reaching the intended destination collector. + +## PAN-313700 + +Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile. + +## PAN-313216 + +Fixed an issue where firewalls with Prisma Access incorrectly displayed some traffic as unsanctioned in traffic logs for cloud applications that were tagged as sanctioned. + +## PAN-312514 + +Fixed an issue where correlation logs were not forwarded via syslog or email. + +## PAN-312354 + +Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to **ERR_CONNECTION_RESET** error messages in the browser with SSL decryption and CTD handshake inspection enabled. diff --git a/web/data/products.json b/web/data/products.json index 99498b8..b09d10b 100644 --- a/web/data/products.json +++ b/web/data/products.json @@ -79,7 +79,8 @@ "11.2.10-h6.md", "11.2.10-h7.md", "11.2.10-h8.md", - "11.2.11.md" + "11.2.11.md", + "11.2.12.md" ], "known": [ "11.2.0.md", @@ -184,7 +185,8 @@ "11.1.13-h3.md", "11.1.13-h5.md", "11.1.13-h6.md", - "11.1.14.md" + "11.1.14.md", + "11.1.15.md" ], "known": [ "11.1.0.md",