CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-0272

criticalcovered by 3 sourcesfirst seen 2026-06-10
View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: RUGGEDCOM APE1808 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.2 Siemens Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-0266 A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability. View CVE Details Affected Products Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Vendor: Siemens Product Version: RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Product Status: known_affected Remediations Vendor fix Contact customer support to receive patch and update information Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 2.4 LOW CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N CVE-2026-0272 A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an

CSIRTS triage

What
Multiple vulnerabilities exist including cross-site scripting and command injection.
Who is affected
Deployments of RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW.
Urgency
Critical remediation is necessary due to the severity of the vulnerabilities.
Action
Consult and implement workarounds provided by Palo Alto Networks.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-0272

Get an email if CVE-2026-0272 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-0272

CVE.org record

Embed the live status

CVE-2026-0272 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-0272 status](https://www.csirts.com/badge/CVE-2026-0272)](https://www.csirts.com/cve/CVE-2026-0272)