A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0256 | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-967325.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-13 19:17
Updated : 2026-07-14 16:39
NVD link : CVE-2026-0256
Mitre link : CVE-2026-0256
CVE.ORG link : CVE-2026-0256
JSON object : View
Products Affected
siemens
- ruggedcom_ape1808_firmware
- ruggedcom_ape1808
paloaltonetworks
- pan-os
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
