imPC@ndo IT

Tracker / CVE-2026-0259

CVE-2026-0259

High 8.8

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

Affected products and versions

paloaltonetworks pan-os
paloaltonetworks pan-os · … → 10.2.7
paloaltonetworks pan-os · 10.2.11 → 10.2.13
paloaltonetworks pan-os · 10.2.14 → 10.2.16
paloaltonetworks pan-os · 10.2.8 → 10.2.10
paloaltonetworks pan-os · 11.1.0 → 11.1.4
paloaltonetworks pan-os · 11.1.11 → 11.1.13
paloaltonetworks pan-os · 11.1.5 → 11.1.6
paloaltonetworks pan-os · 11.1.8 → 11.1.10
paloaltonetworks pan-os · 11.2.0 → 11.2.4
paloaltonetworks pan-os · 11.2.5 → 11.2.7
paloaltonetworks pan-os · 11.2.8 → 11.2.10
paloaltonetworks pan-os · 12.1.0 → 12.1.4
paloaltonetworks pan-os · 12.1.5 → 12.1.7

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References