Junglewise Threat Intelligence

CVE-2026-0258: Palo Alto Networks PAN-OS SSRF in IKEv2 Certificate URL Fetching

CVE-2026-0258 · Severity: info · CVSS 4.8 · Published 2026-05-13

Technologies: Siemens RUGGEDCOM APE1808 Virtual NGFW. Vendors: Palo Alto Networks, Siemens.

Executive brief

A security vulnerability exists in the VPN component of Palo Alto Networks firewalls. An unauthorized attacker can exploit this to force the firewall to send unexpected network requests or crash the device, leading to a service outage. This affects organizations using Site-to-Site VPNs configured with the IKEv2 protocol.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the IKEv2 certificate URL fetching mechanism of PAN-OS. An unauthenticated remote attacker can exploit this by sending specially crafted IKEv2 traffic to a Site-to-Site VPN Gateway. Successful exploitation allows the attacker to force the firewall to initiate network requests to arbitrary destinations or trigger a denial of service (DoS) condition. The vulnerability specifically impacts configurations where IKEv2 is enabled for Site-to-Site VPNs. Patches are available for PAN-OS 10.2, 11.1, 11.2, and 12.1 branches.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1 < 12.1.7, 11.2 < 11.2.4-h17, 11.2 < 11.2.7-h13, 11.2 < 11.2.10-h6, 11.2 < 11.2.12, 11.1 < 11.1.4-h33, 11.1 < 11.1.6-h32, 11.1 < 11.1.7-h6, 11.1 < 11.1.10-h25, 11.1 < 11.1.13-h5, 11.1 < 11.1.15, 10.2 < 10.2.7-h34, 10.2 < 10.2.10-h36, 10.2 < 10.2.13-h21, 10.2 < 10.2.16-h7, 10.2 < 10.2.18-h6
  • Siemens RUGGEDCOM APE1808 Virtual NGFW All versions with Site-to-Site VPN Gateway and IKEv2 configured

Timeline

  • 2026-05-13: advisory: Initial advisory published by Palo Alto Networks
  • 2026-05-13: disclosed: Vulnerability discovered internally by Palo Alto Networks research teams
  • 2026-06-09: advisory: Siemens published secondary advisory for RUGGEDCOM APE1808

References

Related threats