CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

criticalCVE-2026-0266CVE-2026-0272CVE-2026-0273
View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: RUGGEDCOM APE1808 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.2 Siemens Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-0266 A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability. View CVE Details Affected Products Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Vendor: Siemens Product Version: RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Product Status: known_affected Remediations Vendor fix Contact customer support to receive patch and update information Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 2.4 LOW CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N CVE-2026-0272 A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an

CSIRTS triage

What
Multiple vulnerabilities exist including cross-site scripting and command injection.
Who is affected
Deployments of RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW.
Urgency
Critical remediation is necessary due to the severity of the vulnerabilities.
Action
Consult and implement workarounds provided by Palo Alto Networks.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch RUGGEDCOM APE1808

Get an email when a new RUGGEDCOM APE1808 advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-0266coverage & exploitation statusNVD · CVE.org
CVE-2026-0272coverage & exploitation statusNVD · CVE.org
CVE-2026-0273coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories