CVE-2026-0266
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: RUGGEDCOM APE1808 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.2 Siemens Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.13% · 2.9th percentile
Risk Scores
Timeline
- Jun 10, 2026 CVE Published
- Jun 11, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json advisory
- https://www.cve.org/CVERecord?id=CVE-2026-0266 technical
- https://cwe.mitre.org/data/definitions/79.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N technical
- https://www.cve.org/CVERecord?id=CVE-2026-0272 technical
- https://cwe.mitre.org/data/definitions/862.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N technical
- https://www.cve.org/CVERecord?id=CVE-2026-0273 technical
- https://cwe.mitre.org/data/definitions/78.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H technical