Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

Posted on January 15, 2026January 15, 2026 By CWS

Jan 15, 2026Ravie LakshmananNetwork Safety / Vulnerability
Palo Alto Networks has launched safety updates for a high-severity safety flaw impacting GlobalProtect Gateway and Portal, for which it stated there exists a proof-of-concept (PoC) exploit.
The vulnerability, tracked as CVE-2026-0227 (CVSS rating: 7.7), has been described as a denial-of-service (DoS) situation impacting GlobalProtect PAN-OS software program arising because of an improper verify for distinctive situations (CWE-754)
“A vulnerability in Palo Alto Networks PAN-OS software program allows an unauthenticated attacker to trigger a denial-of-service (DoS) to the firewall,” the corporate stated in an advisory launched Wednesday. “Repeated makes an attempt to set off this concern end result within the firewall coming into into upkeep mode.”
The difficulty, found and reported by an unnamed exterior researcher, impacts the next variations –

PAN-OS 12.1 < 12.1.3-h3, < 12.1.4
PAN-OS 11.2 < 11.2.4-h15, < 11.2.7-h8, < 11.2.10-h2
PAN-OS 11.1 < 11.1.4-h27, < 11.1.6-h23, < 11.1.10-h9, < 11.1.13
PAN-OS 10.2 < 10.2.7-h32, < 10.2.10-h30, < 10.2.13-h18, < 10.2.16-h6, < 10.2.18-h1
PAN-OS 10.1 < 10.1.14-h20
Prisma Entry 11.2 < 11.2.7-h8
Prisma Entry 10.2 < 10.2.10-h29

Palo Alto Networks additionally clarified that the vulnerability is relevant solely to PAN-OS NGFW or Prisma Entry configurations with an enabled GlobalProtect gateway or portal. The corporate’s Cloud Subsequent-Era Firewall (NGFW) just isn’t impacted. There aren’t any workarounds to mitigate the flaw.
Whereas there isn’t any proof that the vulnerability has been exploited within the wild, it is important to maintain the units up-to-date, particularly provided that uncovered GlobalProtect gateways have witnessed repeated scanning exercise over the previous yr.

The Hacker News Tags:Alto, Crash, DoS, Firewalls, Fixes, Flaw, GlobalProtect, Login, Palo

Post navigation

Previous Post: Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers
Next Post: Traveler Information Stolen in Eurail Data Breach

Related Posts

Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware The Hacker News
Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks The Hacker News
Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats The Hacker News
ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware The Hacker News
Transforming Your Cybersecurity Practice Into An MRR Machine Transforming Your Cybersecurity Practice Into An MRR Machine The Hacker News
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hack Targets French Government Messaging Platform
  • Microsoft 365 Flaw Risked Email and File Theft
  • Ad Blocker Extensions Secretly Capture AI Chats
  • Cyberattack Disrupts Operations of Major Australian Sugar Producer
  • Weekly Cybersecurity Highlights: Chrome 0-Day & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hack Targets French Government Messaging Platform
  • Microsoft 365 Flaw Risked Email and File Theft
  • Ad Blocker Extensions Secretly Capture AI Chats
  • Cyberattack Disrupts Operations of Major Australian Sugar Producer
  • Weekly Cybersecurity Highlights: Chrome 0-Day & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark