--- type: Addressed product: PAN-OS version: 11.2.12 --- ## BLANK-000000 Fixes were made to address the following CVEs: - [CVE-2026-0265](https://security.paloaltonetworks.com/CVE-2026-0265) - [CVE-2026-0264](https://security.paloaltonetworks.com/CVE-2026-0264) - [CVE-2026-0263](https://security.paloaltonetworks.com/CVE-2026-0263) - [CVE-2026-0262](https://security.paloaltonetworks.com/CVE-2026-0262) - [CVE-2026-0261](https://security.paloaltonetworks.com/CVE-2026-0261) - [CVE-2026-0258](https://security.paloaltonetworks.com/CVE-2026-0258) - [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) - [CVE-2026-0256](https://security.paloaltonetworks.com/CVE-2026-0256) - [CVE-2026-0259](https://security.paloaltonetworks.com/CVE-2026-0259) - [CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300) ## PAN-325120 Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports. ## PAN-322815 ```caveat VM-Series firewalls on Microsoft Azure environments only ``` Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted. ## PAN-318275 ```caveat VM-Series firewalls only ``` Fixed an issue where the firewall became unresponsive and did not automatically reboot, which led to prolonged outages. With this fix, the Linux kernel configuration will trigger a system panic and reboot. ## PAN-317583 Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state. ## PAN-315912 Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized. ## PAN-315176 Added an enable and disable CLI command to address an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic. ## PAN-314319 Added a CLI command to enable and disable AHO software offload optimization. ## PAN-314147 Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU. ## PAN-314018 ```caveat VM-Series firewalls in AWS environments only ``` Fixed an issue where the decrypt mirror port did not function expected, which prevented decrypted traffic from reaching the intended destination collector. ## PAN-313700 Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile. ## PAN-313216 Fixed an issue where firewalls with Prisma Access incorrectly displayed some traffic as unsanctioned in traffic logs for cloud applications that were tagged as sanctioned. ## PAN-312514 Fixed an issue where correlation logs were not forwarded via syslog or email. ## PAN-312354 Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to **ERR_CONNECTION_RESET** error messages in the browser with SSL decryption and CTD handshake inspection enabled.