← All Advisories

Palo Alto Networks PAN-OS External File Path Control Scores 8.8

Last refreshed2026-09-26

Status: NEW  |  Advisory ID: CVE-2026-0259

Key Details

CVECVE-2026-0259
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPalo Alto Networks PAN-OS
Classified asCWE-73 (External Control of File Name or Path)
Exploitation prediction (EPSS)0.34% probability of exploitation in the next 30 days (24% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksPAN-OS
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.

The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.

Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

What to Do

Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0259
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0259
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0259