Sunday, August 23, 2026

China Launches Cybersecurity Review of Palo Alto Networks

Valyrian News Network 6 min read

China Launches Cybersecurity Review of Palo Alto Networks Products

China’s Cyberspace Administration has initiated a formal cybersecurity review of products sold in China by Palo Alto Networks, the US cybersecurity giant headquartered in Santa Clara, California. The announcement, issued Thursday by the Cybersecurity Review Office, cites the need to “ensure the secure and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security.” The review is conducted under China’s National Security Law, Cybersecurity Law, and the Measures for Cybersecurity Review, according to Xinhua. No specific allegations against Palo Alto’s products were disclosed, and no timeline for the review’s conclusion was provided.

The Regulatory Framework

China’s cybersecurity review mechanism was established under the Cybersecurity Review Measures, jointly issued by 13 Chinese government agencies and last revised in December 2021. The review can be triggered voluntarily by operators of critical information infrastructure or proactively by regulators when they determine a product may threaten national security. The People’s Daily published the official announcement, which was also carried by the China News Service.

The most relevant precedent is the Micron Technology case. In March 2023, the Cybersecurity Review Office launched an identical-sounding review of Micron’s products sold in China. Approximately seven weeks later, regulators concluded that Micron’s products posed “relatively serious cybersecurity risks” and directed operators of critical information infrastructure to stop purchasing them. Micron has since effectively exited China’s data center market.

Escalating Pressure on US Cybersecurity Vendors

The formal review follows a January 2026 directive in which Chinese authorities directed domestic organizations to stop using cybersecurity software from more than a dozen US and Israeli companies, including Palo Alto Networks, Fortinet, Check Point, CrowdStrike, VMware, SentinelOne, Mandiant, Recorded Future, and Wiz. The directive, which set a transition deadline for the first half of 2026, cited concerns that Western software could collect and transmit sensitive information abroad.

Palo Alto Networks has maintained a significant presence in China, operating offices in Beijing, Shanghai, Guangzhou, Shenzhen, and Macau, with more than 70 employees. The company provides firewall, VPN, and cloud security services to multinational corporations and large enterprises. However, it is not a mainstream vendor in China’s cybersecurity market, where domestic players like Sangfor, Venustech, H3C, Huawei, and Topsec hold the dominant share.

Security Concerns and Sensitivities

Analysts have identified several factors likely to have drawn Beijing’s attention. Palo Alto’s WildFire service routes file samples and telemetry data to its regional cloud for Asia-Pacific operations, which is based in Singapore rather than mainland China. This means Chinese organizations using Palo Alto products may, by default, send potentially sensitive files and network telemetry outside China’s borders for cloud-based analysis.

More sensitive still is the relationship between Palo Alto’s Unit 42 threat intelligence division and the US government. Unit 42 maintains formal cooperation with the US Department of Homeland Security and the US intelligence community, and has assisted US Department of Justice indictments of Chinese nationals accused of cyberattacks. Reuters reported in February 2026 that Palo Alto executives ordered Unit 42 researchers to soften a threat report, removing a direct attribution of a global espionage campaign affecting 37 countries to Beijing, out of concern that naming China could trigger further retaliation. The company denied that the change was driven by commercial concerns.

Palo Alto has also suffered several serious vulnerabilities that were actively exploited in the wild, including CVE-2024-3400, which allowed unauthenticated attackers to execute code with the highest privileges on certain firewalls, and CVE-2024-3393, which could cause firewalls to reboot repeatedly. Several were added to the US CISA Known Exploited Vulnerabilities catalog.

Broader Geopolitical Context

The cybersecurity review arrives amid escalating US-China trade tensions. On August 5, China’s Ministry of Commerce imposed countersanctions on seven US entities and tightened export controls on drones and related technologies bound for the US, as reported. The measures came in response to US actions including FCC bans on Chinese drones, power inverters, robots, and routers, as well as the addition of more than 40 Chinese entities to the Uyghur Forced Labor Prevention Act list.

William Bratton, an analyst at BNP Paribas, described Beijing as “starting to replicate” Washington’s approach of invoking national security frameworks to restrict access to technology it considers strategically sensitive, according to CNBC. Peter Alexander, founder of Shanghai-based consultancy Z-Ben Advisors, told CNBC that both sides were attempting to come up with new approaches, new sanctions, and new limitations where they could then potentially horse-trade before an expected Xi-Trump summit in Washington anticipated for September.

Potential Outcomes and Financial Impact

Peng Zhang, an analyst writing for GeopolitEchs, identified three possible outcomes for the review. The best case would see the review pass after Palo Alto agrees to a “China edition” of its products with telemetry disabled and full local deployment. The middle case would allow ordinary commercial customers to continue using the products while government and critical infrastructure operators are barred from new procurement. The worst case mirrors Micron: full failure, full ban on critical information infrastructure procurement, and existing customers gradually replaced.

Palo Alto Networks reported $9.22 billion in fiscal year 2025 revenue, with Asia-Pacific accounting for approximately 11.9 percent of total sales. China itself is not separately disclosed, but analysts estimate it represents between one and two percent of total Palo Alto revenue. Shares fell as much as 4.2 percent in pre-market trading before paring some losses, as TechTimes noted.

Even before a verdict, the announcement functions as a de facto pre-verdict restriction. Government agencies, central state-owned enterprises, and operators of critical information infrastructure in finance, energy, telecom, and transport will almost certainly suspend new Palo Alto purchases immediately, pending the review’s outcome.

What to Watch For

The review extends the US-China tech decoupling from hardware—semiconductors, telecom equipment, drones—into the cybersecurity software layer. Cybersecurity products sit at the intersection of network access, data collection, and national security, making them a natural pressure point in the broader geopolitical contest.

Whether Palo Alto can satisfy the review through technical remediation—localizing WildFire infrastructure to mainland China, disabling cross-border telemetry by default, providing source-code access for Chinese security testing—remains an open question. The company has stated it supports “the highest standards of business conduct, security practices and ethics in all our global operations.” The review’s outcome, and its timing relative to the anticipated Xi-Trump summit in September, will signal whether Beijing seeks a negotiated resolution or a decisive verdict in what is becoming a defining front of the US-China technology war.