Add latest releases

This commit is contained in:
2026-05-15 09:34:02 -05:00
parent f7467995cb
commit e86259ffad
34 changed files with 5405 additions and 308 deletions
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security logs incorrectly displayed a
sinkhole action for benign DNS categories due to the firewall saving
the drop or sinkhole action in session flags without discarding the
session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect host ID field was
intermittently blank in traffic logs on Prisma Access, even when the
user was connected and had the correct host ID information. This
occurred when the IP address to host ID entry expired and the entry
was re-inserted without the dataplane flag being set.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195264</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the login lifetime countdown timer reset when
using an authentication override cookie to log in to the gateway.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,54 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-312703</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where failures between
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
and
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
processes could lead to intermittent loss of User-ID and HIP Match
logs during log spikes.
</div>
</td>
</tr>
</tbody>
</table>
+139
View File
@@ -0,0 +1,139 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan-os-10-2-10-h31-addressed-issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,35 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 38%" />
<col style="width: 62%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306502</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connection failure occurred when traffic was
over TLS1.2 or below, header insertion was enabled on the firewall,
<span class="ph uicontrol">send TLS handshake to CTD</span> was
enabled, and traffic hit a decryption policy rule configured with the
<span class="ph uicontrol">no-decrypt</span> action.
</div>
</td>
</tr>
</tbody>
</table>
+405
View File
@@ -0,0 +1,405 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-312706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Strata Logging Service (SLS) even when duplicate
logging and enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama incorrectly generated system logs
indicating a lost connection to its peer after an upgrade even when
High Availability was not configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP peering sessions between a hub firewall and a
satellite firewall over GlobalProtect LSVPN failed to connect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305415</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits caused high dataplane CPU utilization and
briefly increased Packet Descriptors, which disrupted traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you disabled the shared
optimization feature, a full configuration push to multi-vsys devices
caused a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303051</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process due to retaining memory that was temporarily used for report
generation instead of releasing the memory for reuse, which resulted
in continuous accumulation and memory exhaustion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to perform a selective push to a
managed device when device tags were added or modified on the policy
rules. The selective push would fail with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic reports that were generated with
destination/source and destination/source hostnames were not displayed
in IPv4 format.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive after an upgrade
due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>fsck</a
>
command scanning drive partitions in parallel with the root partition,
which caused the process to take an extended amount of time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295470</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process continuously increased its memory consumption, which resulted
in an OOM condition that caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291009</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a web server returned a 401 or 403 error,
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
rejected all subsequent streams from the client.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a cumulative memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process that occurred whenever the CLI command
<span class="ph systemoutput"
>show running application statistics</span
>
was issued. This memory leak would gradually consume system memory and
produce an OOM condition, causing the firewall to reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280196</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in Prisma Access environments where the firewall
matched a HIP object but not on the HIP profile that contained the
object.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274742</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the <span class="ph systemoutput">task-queue dump</span> CLI command
returned incorrect information in multi-nic mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252809</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a single PIM neighbor was sending 0.0.0.0 as its
address, which occurred because an improvement in PIM neighbor address
selection did not correctly account for configurations with a single
IP address.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242952</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high SSL traffic depleted flex memory, which
prevented the firewall from revalidating SSLVPN client CAs during
configuration pushes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-230748</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the current time as the
expiration date for an imported certificate in the CLI output instead
of the correct expiry time due to an improper use of an OpenSSL
library function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202911</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a satellite tunnel was not established after
turning on satellite firewalls.
</div>
</td>
</tr>
</tbody>
</table>
+139
View File
@@ -0,0 +1,139 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan-os-10-2-10-h31-addressed-issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
</tbody>
</table>
+406
View File
@@ -0,0 +1,406 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manuallly creating a device telemetry
bundle, the
<span class="ph systemoutput">hour_cli_output.txt</span> file within
the bundle had a file size of 0 bytes. This occurred when checking the
bundle content after enabling device telemetry and setting the device
telemetry upload endpoint.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301018</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where API queries for correlated category
logs incorrectly returned a count of 0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300055</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced high disk utilization in
the /opt/pancfg/mgmt/content-preview directory due to older content
data not being automatically removed when an error occurred during the
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected PAN-OS release,
the Visible Virtual System field referenced the vsys name instead of
the vsys ID, which caused inter-vsys routing to fail. This occurred
when a vsys display name matched one of the vsys IDs. If you're using
a multivsys environment, you must upgrade your firewalls to a fixed
PAN-OS version. The best practice is to upgrade both the firewalls and
Panorama to a fixed PAN-OS version.
</div>
<ul class="ul">
<li class="li">
If you don't upgrade Panorama to a fixed version, you'll encounter
PAN-245064, where a commit on a multivsys firewall fails with the
message
<span class="ph systemoutput"
>vsys name should end with a number vsys is invalid</span
>
after you
<span class="ph uicontrol"
>Export or push device config bundle</span
>
from 11.1.1 Panorama.
</li>
<li class="li">
After you upgrade Panorama to a fixed version, you'll encounter
PAN-214177, which causes an
<span class="ph uicontrol"
>Export or Push device config bundle</span
>
from Panorama to the firewall to fail. The workaround for PAN-214177
is to first push only the template configuration and then push the
device group configurations.
</li>
</ul>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297609</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the the CLI command
<span class="ph systemoutput"
>debug user-id refresh user-id agent all</span
>
failed with the error message
<span class="ph systemoutput"
>Invalid agent name. Agent name should be 1 to 31 characters
long.</span
>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the proxy-protocol debug level was set to
<span class="ph systemoutput">verbose</span> on Prisma Access
instances, even when it was not explicitly configured, which caused
excessive logging by the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295095</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you used a syslog forwarding profile with
the CEF format, an additional string was appended to the end of the
log message when viewing the log entry from the Universal Forwarder
directory.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295049</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding due to memory allocation errors during
Redis communication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with the
<span class="ph uicontrol"
>Send handshake messages to CTD for inspection</span
>
setting enabled caused incorrect security policy rules to be matched.
Specifically, traffic not identified as openai-base or openai-chatgpt
applications was incorrectly matched by the
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
response page for blocked URLs was not displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291172</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrators were unable to gather path
monitoring failure information when troubleshooting high dataplane CPU
utilization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290665</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama in a High Availability
(HA) pair, the configuration logs stopped synchronizing from the
primary Panorama to the secondary Panorama. This issue occurred
because the log forwarding flag was permanently disabled due to the
connection state not being active when the
<span class="ph systemoutput">log-fwd-ctrl</span> message was
received.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where API jobs failed with the error
message
<span class="ph systemoutput"
>Server error: Timed out while getting config lock</span
>. This occurred due to slow set request performance when setting a
large number of address objects in a single set call.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs incorrectly displayed the action as
<span class="ph uicontrol">allow</span> for traffic matching a
Security policy rule configured with the action set to
<span class="ph uicontrol">deny</span>. This issue occurred due to the
child session being used for policy rule lookup when a configuration
update triggered a rematch if the FTP-data application was not in the
rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281588</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packet buffer depletion occurred due to the a
high number of
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266843</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on airgapped firewalls where cloud connection errors
flooded the system logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262353</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Panorama was upgraded to PAN-OS 10.2.10,
and log collectors were on PAN-OS 10.2.9-h1, logs from a log collector
group were not viewable on a Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237349</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URLs with over 965 characters were unable to be
logged in the URL filtering log.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233542</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not display the source address
due to an uninitialized scalar variable.
</div>
</td>
</tr>
</tbody>
</table>
+341
View File
@@ -0,0 +1,341 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan_os_11_1_13_h5_addressed_issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-323243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
crash occurred when the
<span class="ph uicontrol">Policies &gt; Security</span> view was
updated or refreshed in the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317215</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on ESXi with Intel E810 NICs using PCI
passthrough</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
process became unresponsive during data port initialization, which
resulted in system instability, interface outages, HA split-brain
conditions, and unexpected reboots during failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-317155</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the link status of log port 1 and log port 2 were
unable to be monitored via SNMP due to the OIDs for the individual
ports not being available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314875</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
firewall logs were not visible in the Strata Logging Service even
though cloud logging was enabled and the firewall was successfully
forwarding logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch did not properly apply updated
Security policy rules to existing traffic flows after committing
changes, which caused traffic to still be allowed when a new Security
policy was set to <span class="ph uicontrol">Deny</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311166</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task_1</a
>
process repeatedly restarting.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-310472</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where checkboxes for
<span class="ph uicontrol">default information originate</span> and
ABR in OSPF NSSA configurations were automatically enabled which
resulted in unexpected configuration changes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308377</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue where the firewall reached 100% disk utilization due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process repeatedly restarting and dumping core files due to a blocked
hints processing thread, which caused a failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307714</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
insufficient i-node space was available on the sysroot0 partition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302196</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding when cleaning up
expired sessions currently in Advanced Threat Prevention hold mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not match the correct policy for
SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
10.2.9-h1 to PAN-OS 11.2.3.
</div>
</td>
</tr>
</tbody>
</table>
+440
View File
@@ -0,0 +1,440 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan_os_11_1_13_h5_addressed_issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-323243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
crash occurred when the
<span class="ph uicontrol">Policies &gt; Security</span> view was
updated or refreshed in the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-318567</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the OpenConfig plugin stopped working after a
configuration update.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317583</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with intermittent ICMP ping drops and packet loss in
traffic flows between a hub and branch after upgrading to an affected
PAN-OS release due to incorrect SD-WAN path monitor state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SIP sessions stopped progressing after the
firewall received fragmented packets, fragmented at header field.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317215</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on ESXi with Intel E810 NICs using PCI
passthrough</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
process became unresponsive during data port initialization, which
resulted in system instability, interface outages, HA split-brain
conditions, and unexpected reboots during failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317177</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in DHCP Client mode where, after upgrading
to an affected release, the SNMP process unexpectedly restarted after
a commit, which led to false interface flap notifications on SNMP
managers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-317155</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the link status of log port 1 and log port 2 were
unable to be monitored via SNMP due to the OIDs for the individual
ports not being available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-316631</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue BGP sessions experienced short disruptions across all
peers, interfaces, and slots when a multicast event persisted longer
than the NGP negotiated hold timers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314875</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
firewall logs were not visible in the Strata Logging Service even
though cloud logging was enabled and the firewall was successfully
forwarding logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314435</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where custom application
tags for cloud applications were not consistently displayed in the
Application Filter or application details even though the tags were
configured via CLI and successfully enforced traffic blocking policy
rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch did not properly apply updated
Security policy rules to existing traffic flows after committing
changes, which caused traffic to still be allowed when a new Security
policy was set to <span class="ph uicontrol">Deny</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313193</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in Layer 2 mode only</tt>) Fixed an issue
where the new sessions were not able to be established due to the
firewall intermittently dropping valid MAC address entries for
specific VLANs when a manual switchover sent a high volume of traffic
to the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311248</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ABR failed to translate and advertise the
default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF
backbone area as a Type-5 LSA.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-310472</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where checkboxes for
<span class="ph uicontrol">default information originate</span> and
ABR in OSPF NSSA configurations were automatically enabled which
resulted in unexpected configuration changes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308377</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue where the firewall reached 100% disk utilization due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process repeatedly restarting and dumping core files due to a blocked
hints processing thread, which caused a failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307714</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
insufficient i-node space was available on the sysroot0 partition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295728</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuring an OSPFv2 NSSA area range caused
OSPF-learned routes to become unreachable due to the incorrect
installation of a discard route when the NSSA range prefix matched an
existing OSPF route.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295309</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF session using MD5 authentication experienced
intermittent flapping due to out-of-order packet processing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not match the correct policy for
SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
10.2.9-h1 to PAN-OS 11.2.3.
</div>
</td>
</tr>
</tbody>
</table>
+163
View File
@@ -0,0 +1,163 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan_os_11_1_4_h33_addressed_issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265399 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS queries for uppercase internal domain (SRV
record) timed out when DNS Security was enabled.
</div>
</td>
</tr>
</tbody>
</table>
+286
View File
@@ -0,0 +1,286 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan_os_11_1_13_h5_addressed_issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-323243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
crash occurred when the
<span class="ph uicontrol">Policies &gt; Security</span> view was
updated or refreshed in the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-322281</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the HA 2 interface did not come up on the passive
firewall, which resulted in the firewall being unable to join the HA
pair.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch did not properly apply updated
Security policy rules to existing traffic flows after committing
changes, which caused traffic to still be allowed when a new Security
policy was set to <span class="ph uicontrol">Deny</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311166</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task_1</a
>
process repeatedly restarting.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308377</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue where the firewall reached 100% disk utilization due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process repeatedly restarting and dumping core files due to a blocked
hints processing thread, which caused a failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307901 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a leak in decryption counters caused resource
exhaustion, which led to a GlobalProtect service outage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307714</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
insufficient i-node space was available on the sysroot0 partition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302196</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding when cleaning up
expired sessions currently in Advanced Threat Prevention hold mode.
</div>
</td>
</tr>
</tbody>
</table>
+29
View File
@@ -0,0 +1,29 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">This hotfix includes performance and bug fixes.</div>
</td>
</tr>
</tbody>
</table>
+321
View File
@@ -0,0 +1,321 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan_os_11_2_10_h6_addressed_issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317215</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on ESXi with Intel E810 NICs using PCI
passthrough</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
process became unresponsive during data port initialization, which
resulted in system instability, interface outages, HA split-brain
conditions, and unexpected reboots during failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-315919</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect pre-logon tunnel session was not
cleared even after the user was logged in. With this fix, the session
is cleared after the session timeout expires.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process exited unexpectedly when handling syslog forwarding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311192</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>device-telemetry collect-now</a
>
process became unresponsive when the process was initiated multiple
times with other processes running concurrently, which prevented
subsequent telemetry collection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308377</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue where the firewall reached 100% disk utilization due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process repeatedly restarting and dumping core files due to a blocked
hints processing thread, which caused a failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306356</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process on a firewall stopped responding due to a document node being
unexpectedly freed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303663</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SolarWinds monitoring systems
reported 100% usage for Slot1 Data Processor-0 Hardware Packet Buffers
due to an inaccurate reported packet buffer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295806</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process occurred due to a hash insert operation failing during
connection management and SSL connections.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a stack buffer overflow memory leak under plugin management
code path.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+308
View File
@@ -0,0 +1,308 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan_os_11_2_7_h13_addressed_issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a fix to improve performance in lossy network conditions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-315965</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue to address TCP proxy fast recovery behavior to follow
RFC 5681.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-315919</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect pre-logon tunnel session was not
cleared even after the user was logged in. With this fix, the session
is cleared after the session timeout expires.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311192</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>device-telemetry collect-now</a
>
process became unresponsive when the process was initiated multiple
times with other processes running concurrently, which prevented
subsequent telemetry collection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308377</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue where the firewall reached 100% disk utilization due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process repeatedly restarting and dumping core files due to a blocked
hints processing thread, which caused a failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306356</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process on a firewall stopped responding due to a document node being
unexpectedly freed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303663</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SolarWinds monitoring systems
reported 100% usage for Slot1 Data Processor-0 Hardware Packet Buffers
due to an inaccurate reported packet buffer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295806</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process occurred due to a hash insert operation failing during
connection management and SSL connections.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a stack buffer overflow memory leak under plugin management
code path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251024</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect logs did not show the correct
region for the IP address due to content updates not retrieving the
latest configuration.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+139
View File
@@ -0,0 +1,139 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="panos-addressed-issues-12.1.3_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0263"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0263</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
</ul>
</td>
</tr>
</tbody>
</table>