Status: UPDATED | Advisory ID: CVE-2026-0258
| CVE | CVE-2026-0258 |
| CVSS | CVSS 9.1 (Critical). |
| Affected products | Siemens RUGGEDCOM APE1808 Firmware and Palo Alto Networks PAN-OS |
| Classified as | CWE-918 (Server-Side Request Forgery (SSRF)) |
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.
Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-0258 |
| Vendor advisory | https://security.paloaltonetworks.com/CVE-2026-0258 |