--- type: Addressed product: PAN-OS version: 11.2.7-h18 --- ## BLANK-000000 Fixes were made to address the following CVEs: - [CVE-2026-0283](https://security.paloaltonetworks.com/CVE-2026-0283) - [CVE-2026-0287](https://security.paloaltonetworks.com/CVE-2026-0287) - [CVE-2026-0279](https://security.paloaltonetworks.com/CVE-2026-0279) - [CVE-2026-0282](https://security.paloaltonetworks.com/CVE-2026-0282) - [CVE-2026-0288](https://security.paloaltonetworks.com/CVE-2026-0288) - [CVE-2026-0286](https://security.paloaltonetworks.com/CVE-2026-0286) - [CVE-2026-0285](https://security.paloaltonetworks.com/CVE-2026-0285) - [CVE-2026-0280](https://security.paloaltonetworks.com/CVE-2026-0280) - [CVE-2026-0284](https://security.paloaltonetworks.com/CVE-2026-0284) - [CVE-2026-0281](https://security.paloaltonetworks.com/CVE-2026-0281) ## PAN-308775 ```caveat Firewalls in active/passive configurations only ``` Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time. ## PAN-308606 Fixed an issue where traffic was blocked due to a mismatch between the URL category specified in the Security policy rule and the URL filter profile when custom URL categories with the same FQDN were configured. ## PAN-295854 Fixed an issue where the firewall generated two URL logs for a single session. ## PAN-293707 Fixed an issue where the iotd process failed to install DPI Cloud server FQDN due to a configuration parsing failure, caused by the configuration XML memory buffer not being NULL terminated. This resulted in the accumulation of EAL logs and DLP forwarding being stopped. ## PAN-289895 Fixed an issue where, when SSL decryption was enabled, traffic matching a deny rule was incorrectly allowed until the SSL handshake was complete.