A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.
Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0258 | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-967325.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-13 19:17
Updated : 2026-07-14 15:52
NVD link : CVE-2026-0258
Mitre link : CVE-2026-0258
CVE.ORG link : CVE-2026-0258
JSON object : View
Products Affected
siemens
- ruggedcom_ape1808_firmware
- ruggedcom_ape1808
paloaltonetworks
- pan-os
CWE
CWE-918
Server-Side Request Forgery (SSRF)
