u/Sure-Squirrel8384

PAN-OS 10.2.18-h9 released

PAN-OS 10.2.18-h9 was released (for hardware that still has support, e.g. PA-220).

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-18-known-and-addressed-issues/pan-os-10-2-18-h9-addressed-issues

PAN-329698 (OCTEON, MIPS, platforms only) Fixed an issue where the data plane became unresponsive. With this fix, the data plane operates stably.
PAN-308775 (Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time.

We have not experienced unresponsive data planes with our PA-220 (OCTEON-based CPU).

We have not experienced problems with NTP on our PA-220 in A/P.

We have recently moved from 10.2.16-h7 to 10.2.16-h9, as 10.2.16-hX is still the preferred release for 10.2. I see no CVEs listed in 10.2.16-h9, so we'll still not be moving beyond 10.2.16-hX.

https://security.paloaltonetworks.com/?version=PAN-OS+10.2.16-h9&product=PAN-OS&sort=-date

docs.paloaltonetworks.com
u/Sure-Squirrel8384 — 4 days ago

Anyone running 11.1.13-h9?

11.1.13-h9 will be our first move to 11.1.13-hX.

We've been on 11.1.10-hX since 11.1.10-h1 went Preferred (I believe we started at 11.1.10-h3 as we always delay some months before moving minor versions) and have upgraded to various hotfixes about once a month or so, with our final install at 11.1.10-h26.

11.1.13 (w/o hotfix) went preferred Jan 15. We typically wait 6 months before moving. We we do move, we go to the latest hotfix for a preferred minor release, at least once it's been out for a few weeks. 11.1.13-h3 went preferred Apr 21; 11.1.13-h9 released July 6 so its had two full weeks. It addresses two more CVEs not fixed in previous 11.1.10-hXX or 11.1.13-hX releases.

Any problems spotted so far with 11.1.13-h9? We rolled it out to our various Test/Lab and firewalls with the least impact, and no problems so far.

reddit.com
u/Sure-Squirrel8384 — 6 days ago
▲ 60 r/vmware

HPE SPP warning for VMware ESXi w/SecureBoot

Warning for those with HPE servers. Before you apply the latest SPP2026050000.2026 you need to first apply the ESXi "j" patch. This is likely true of Dell and other vendors.

If you do not, you will end up with errors such as this and ESXi will fail to be recognized as a valid boot partition (and the system isn't obvious, this came via the iLO logs / email alerts):

Secure Boot Authentication Failure - The image on Slot 2 Port 1 failed authentication and was not executed.

ACTION: Update the image to known good trusted version. If current image is trusted, then update the Secure Boot allowed database (DB) with the certificate or image hash.

The fix is easy, but a waste of time and can be avoided. You must boot the the currently installed ESXi ISO, select your boot partition, once it is detected use the "Upgrade and preserve data" option. Note that this can even blow up if you patch to "j" and also SPP2026050000.2026 at the same time. You must do "j" first and reboot clean before patching with SPP2026050000.2026 (ask me how I know).

Also note that if you patch to "j" then you cannot use the OEM HPE ISO as there isn't one for "j" (they often skip a number of releases) and the latest OEM HPE IOS for "i" will fail to work as a recovery media and you'll have to use the generic "j" ISO.

reddit.com
u/Sure-Squirrel8384 — 30 days ago

New PAN-OS CVEs

CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI (Severity: MEDIUM)

https://security.paloaltonetworks.com/CVE-2026-0273

CVE-2026-0272 PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI) (Severity: MEDIUM)

https://security.paloaltonetworks.com/CVE-2026-0272

CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing (Severity: MEDIUM)

https://security.paloaltonetworks.com/CVE-2026-0269

CVE-2026-0266 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface (Severity: LOW)

https://security.paloaltonetworks.com/CVE-2026-0266

u/Sure-Squirrel8384 — 2 months ago

PAN-OS 11.1.7-h6, 11.1.10-h26, 11.1.13-h6, 11.2.4-h17, 11.2.7-h15 & 11.2.10-h8 are now available!

Seems like just 8 days ago the last hotfixes came out. We have the last releases in Test, but haven't rolled to Prod. Guess we'll be skipping the last and going to these.

The PAN-OS 11.1.7-h6, 11.1.10-h26, 11.1.13-h6, 11.2.4-h17, 11.2.7-h15 & 11.2.10-h8 software updates are now available on the Palo Alto Networks Software Updates page.

Check out the following Release Notes for release details, including the new features and bug fixes that make the upgrade worthwhile:

  • 11.1.7-h6 (Long list of CVEs)
  • 11.1.10-h26 (fixes for Eth1/1 data port and PoE ports, don't use -h25)
  • 11.1.13-h6 (fixes for Eth1/1 data port and PoE ports, don't use -h5)
  • 11.2.4-h17 (Long list of CVEs)
  • 11.2.7-h15 (fixes for Eth1/1 data port and PoE ports, don't use -h14)
  • 11.2.10-h8 (fixes for Eth1/1 data port and PoE ports, don't use -h7)

CVEs:

reddit.com
u/Sure-Squirrel8384 — 2 months ago