CVE-2026-0258: Palo Alto Networks PAN-OS
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.
Affected products
- Palo Alto Networks PAN-OS: before 10.2.7 (fixed in 10.2.7); from 10.2.8, before 10.2.10 (fixed in 10.2.10); from 10.2.11, before 10.2.13 (fixed in 10.2.13); from 10.2.14, before 10.2.16 (fixed in 10.2.16); version 10.2.7 only; version 10.2.10 only; …
- Siemens Ruggedcom APE1808 Firmware: affected versions not specified
Published 2026-05-13. Last modified 2026-07-14.