July 14, 2026

Recommendation for Palo Alto Devices

No items found.

July 14, 2026

Note: We will continue to monitor for vulnerabilities affecting Palo Alto Networks PAN-OS Firewalls and send communications regarding out-of-cycle upgrades when needed. The next regularly scheduled Upkeep tech review for Palo Alto devices will be in October 2026.

As part of UpKeep, our feature to keep our NWG Manage customers' devices on the latest stable version, we reviewed the latest Palo Alto releases and recommend the upgrades detailed below.

Why Are You Sharing This Information?

Even if we're not managing Palo Alto devices for you, we want you to have the latest information to help keep your devices secure.

  • What should I do if I have a Palo Alto device that NWG manages?
    If you have a Palo Alto device(s) that we manage for you, we already know what hardware you have and what version you need to be on. We’ll handle the upgrade during an upcoming maintenance window (unless you are already running the recommended version). Zendesk notifications will be sent out once maintenance has been scheduled, including details about when implementation will take place. If your devices/locations require different days/times for maintenance to take place, you’ll receive separate tickets.
  • What if I have Panorama devices that NWG manages?
    If you have Panorama devices, they will receive an upgrade one week prior to the additional Palo Alto device upgrades outlined below. You’ll receive Zendesk notifications for both.
  • What if I have a Palo Alto device that NWG does not manage?
    If you have a Palo Alto device(s) in your environment, we suggest you upgrade to the recommended version listed below.
  • What if I don't have any Palo Alto devices?
    If you don't have any Palo Alto devices, no action is needed.

Which Palo Alto Releases Do You Recommend?

  • PanOS 12.1.4-h8 for fifth-generation hardware (currently PA-55XX and PA-5XX).
  • PanOS 11.2.10-h12 for all devices that require 11.2.X.
  • PanOS 11.1.13-h9 for all devices that are capable of running 11.1.X.
  • PanOS 10.2.16-h9 for all devices that are capable of running 10.2.X. PanOS 10.2.X is in extended support and should only be used for devices not capable of running 11.1.X. Any devices not capable of running at least 11.1.X should be targeted for replacement. 
  • PanOS 10.1.X is end of life and should no longer be used.

These versions are the most stable and they remediate several vulnerabilities listed in the Review Details section below. 

Review Details

Note: PanOS version compatibility is dependent on hardware. Newer hardware is not capable of running older versions of PanOS. Virtual Palo Alto firewalls do not have this limitation. The compatibility matrix can be found at: https://docs.paloaltonetworks.com/compatibility-matrix/reference/supported-os-releases-by-model/palo-alto-networks-next-gen-firewalls

PanOS 12.X

PanOS 12.X Review

This version is the required version for fifth-generation hardware (currently PA-55XX and PA-5XX). These hardware platforms require 12.X and cannot run older versions. The most current release is 12.1.8.

PanOS 12.X Conclusion

NWG recommends PanOS 12.1.4-h8 for fifth-generation hardware at this time as this release remediates the following vulnerabilities:

  • CVE-2026-0280
    • PAN-OS: IPv6 Firewall Policy Bypass
  • CVE-2026-0283
    • PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0284
    • PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0285
    • PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
  • CVE-2026-0286
    • PAN-OS: Authenticated Command Injection in CLI
  • CVE-2026-0287
    • PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
  • CVE-2026-0288
    • PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

PanOS 11.2

PanOS 11.2 Review

The current Palo Alto recommended version is 11.2.10-h3. PanOS 11.2.13 is the newest version, but 11.2.10-x is the most mature version.

PanOS 11.2 Conclusion

NWG recommends PanOS 11.2.10-h12 for all devices that require PanOS 11.2.X. PanOS 11.2.10-h12 is the most stable version and remediates the following vulnerabilities:

  • CVE-2026-0280
    • PAN-OS: IPv6 Firewall Policy Bypass
  • CVE-2026-0283
    • PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0284
    • PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0285
    • PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
  • CVE-2026-0286
    • PAN-OS: Authenticated Command Injection in CLI
  • CVE-2026-0287
    • PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
  • CVE-2026-0288
    • PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

PanOS 11.2.X only has a ~12% adoption rate across Palo Alto platforms. NWG recommends earlier versions of PanOS where possible.

PanOS 11.1

PanOS 11.1 Review

The current Palo Alto recommended version is 11.1.13-h3. PanOS 11.1.16 is the newest version.

PanOS 11.1 Conclusion

NWG recommends PanOS 11.1.13-h9 for all devices that are capable of running 11.1. PanOS 11.1.13-h9 is the most stable version and remediates the following vulnerabilities:

  • CVE-2026-0280
    • PAN-OS: IPv6 Firewall Policy Bypass
  • CVE-2026-0283
    • PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0284
    • PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0285
    • PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
  • CVE-2026-0286
    • PAN-OS: Authenticated Command Injection in CLI
  • CVE-2026-0287
    • PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
  • CVE-2026-0288
    • PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

PanOS 11.1.13-h9 also resolved the following issues:

  • Issue ID: PAN-308876
    • Fixed an issue where upgrades to managed firewalls from Panorama failed.
  • Issue ID: PAN-286386
    • Fixed an issue where GlobalProtect users were unable to connect
  • Issue ID: PAN-285327
    • Fixed an issue where a memory leak occurred when processing device and vsys tags.

PanOS 11.1.X has the highest adoption rate across Palo Alto platforms. 

PanOS 10.2

PanOS 10.2 Review

The current Palo Alto recommended version is 10.2.16-h6. PanOS 10.2.18-h8 is the newest version, which was released on 7/5/26, and has some known issues that have a high impact. The issues are:

Known 10.2.18 Issues:

Bug ID: PAN-303959

Traffic that is incorrectly identified as unknown-tcp/unknown-udp eventually drops due to an App-ID resource limitation issue.

Bug ID: PAN-297610

A firewall may become unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, causing the process to take an extended amount of time.

Bug ID: PAN-284067

A cumulative memory leak in the devsrvr process gets progressively worse whenever the CLI command show running application statistics is issued. This memory leak will gradually consume system memory and produce an out-of-memory (OOM) condition, leading to an eventual firewall reboot.

Workaround: Avoid using the CLI command: show running application statistics.

Bug ID: PAN-189076

On a firewall with Advanced Routing enabled, OSPFv3 peers using a broadcast link and a designated router (DR) priority of 0 (zero) are stuck in a two-way state after HA failover.

Workaround: Configure at least one OSPFv3 neighbor with a non-zero priority setting in the same broadcast domain.

PanOS 10.2 Conclusion

NWG recommends PanOS 10.2.16-h9 for all devices that are capable of running 10.2. PanoOS 10.2.16-h9 is the most stable version and remediates the following vulnerabilities:

  • CVE-2026-0280
    • PAN-OS: IPv6 Firewall Policy Bypass
  • CVE-2026-0283
    • PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0284
    • PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
  • CVE-2026-0285
    • PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
  • CVE-2026-0286
    • PAN-OS: Authenticated Command Injection in CLI
  • CVE-2026-0287
    • PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
  • CVE-2026-0288
    • PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

End of standard support for PanOS 10.2.X was 8/27/25. It is now in extended support and should only be used for devices that are not capable of running 11.1.X. Any devices not capable of running at least 11.1.X should be targeted for replacement.

PanOS 10.1

PanOS 10.1 Review

PanOS 10.1 is End of Life and should no longer be used.

PanOS 10.1 Conclusion

NWG recommends replacing any devices that are not capable of running at least PanOS 11.1.X.

Review Process

  • Model Evaluation
    • Determines major code revision compatibility
  • Newest Version (Mature/GA)
    • Evaluate known issues
    • Evaluate resolved issues
    • Evaluate features as needed

Think We Can Help?

Let’s Talk