Status: NEW | Advisory ID: CVE-2026-0259
| CVE | CVE-2026-0259 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Palo Alto Networks PAN-OS |
| Classified as | CWE-73 (External Control of File Name or Path) |
| Exploitation prediction (EPSS) | 0.34% probability of exploitation in the next 30 days (24% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Palo Alto Networks | PAN-OS |
| Subsystems | General OT |
| Sectors | Multi-sector |
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.
The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.
Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.
Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-0259 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-0259 |
| Vendor advisory | https://security.paloaltonetworks.com/CVE-2026-0259 |